Security: gitpython-developers/GitPython
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()GHSA-539m-9xh6-q6rr published
Jul 26, 2026 by ByronModerate -
Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file readGHSA-3f7w-8rr8-f37f published
Jul 26, 2026 by ByronHigh -
Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countGHSA-p538-c434-8v24 published
Jul 25, 2026 by ByronModerate -
Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)GHSA-94p4-4cq8-9g67 published
Jul 23, 2026 by ByronHigh -
Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksGHSA-6p8h-3wgx-97gf published
Jul 22, 2026 by ByronHigh -
Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)GHSA-fjr4-x663-mwxc published
Jul 22, 2026 by ByronHigh -
Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executionGHSA-r9mr-m37c-5fr3 published
Jul 22, 2026 by ByronHigh -
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)GHSA-3rp5-jjmw-4wv2 published
Jul 20, 2026 by ByronHigh -
Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLGHSA-rwj8-pgh3-r573 published
Jul 16, 2026 by ByronHigh -
command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`GHSA-956x-8gvw-wg5v published
Jul 12, 2026 by ByronHigh