gitpython vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WVPP-8HX9-P66JHighGitPython: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command executionGHSA-JM78-9FVV-MHGRHighGitPython: GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)GHSA-HMQ2-W58F-27JCHighGitPython: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPythonGHSA-HH9P-6WH2-4MFCMediumGitPython: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()GHSA-9RJ7-RF2P-W77RHighGitPython: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooksGHSA-4GMW-GG2M-W46PHighGitPython: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwriteGHSA-P538-C434-8V24MediumGitPython: GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countGHSA-539M-9XH6-Q6RRMediumGitPython: GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via…GHSA-3F7W-8RR8-F37FHighGitPython: GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary…GHSA-94P4-4CQ8-9G67HighGitPython: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)GHSA-R9MR-M37C-5FR3HighGitPython: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executionGHSA-6P8H-3WGX-97GFHighGitPython: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksGHSA-FJR4-X663-MWXCHighGitPython: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)GHSA-3RP5-JJMW-4WV2Highgitpython: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)GHSA-RWJ8-PGH3-R573Highgitpython: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLGHSA-956X-8GVW-WG5VHighGitPython: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via…GHSA-2F96-G7MH-G2HXHighGitPython: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistGHSA-V396-V7Q4-X2QJHighGitPython: GitPython unsafe clone option gate bypass through joined short optionsGHSA-MV93-W799-CJ2WHighGitPython: GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPathCVE-2026-44244HighGitPython: GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathCVE-2026-44243HighGitPython: GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repositoryCVE-2026-42215HighGitPython: GitPython has Command Injection via Git options bypassCVE-2026-42284HighGitPython: GitPython: Unsafe option check validates multi_options before shlex.split transformationCVE-2024-22190HighGitPython: Untrusted search path under some conditions on Windows allows arbitrary code executionCVE-2023-41040MediumGitPython: GitPython blind local file inclusion

Stop the waste.
Protect your environment with Kodem.