LIVE · cybersecurity feed
Live wire
vendor

Gitpython Project

16 CVEs published in the last four months. Exploited flaws first.

Critical2
High14
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-786769.8criticalgitpythonGitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupt12d ago
CVE-2026-673249.8criticalgitpythonGitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<35d ago
CVE-2026-762218.8highgitpythonGitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows at17d ago
CVE-2026-736258.8highgitpythonGitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard t23d ago
CVE-2026-673258.8highgitpythonGitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-op35d ago
CVE-2026-762208.8highgitpythonGitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be b17d ago
CVE-2026-786758.4highgitpythonGitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose l12d ago
CVE-2026-673238.4highgitpythonGitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive()35d ago
CVE-2026-762228.2highgitpythonGitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git17d ago
CVE-2026-762198.1highgitpythonGitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFi17d ago
CVE-2026-736208.1highgitpythonGitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), al23d ago
CVE-2026-786777.5highgitpythonGitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbit12d ago
CVE-2026-736227.5highgitpythonGitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL23d ago
CVE-2026-736237.5highgitpythonGitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowin23d ago
CVE-2026-762187.5highgitpythonGitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git optio17d ago
CVE-2026-673227.5highgitpythonGitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from().35d ago

Filter the full tracker by Gitpython Project