PT-2026-71447 · Pypi+1 · Gitpython+1

·

CVE-2026-73619

·

Published

2026-07-26

·

Updated

2026-09-03

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.57
Description An incomplete denylist in the unsafe git archive options guard allows attackers to provide the --add-file and --add-virtual-file options to the Repo.archive() function. This can be exploited to read arbitrary files from the filesystem and include them in the generated archive.
Recommendations Update GitPython to version 3.1.57 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11718
CVE-2026-73619
GHSA-539M-9XH6-Q6RR
OPENSUSE-SU-2026:11566-1
PYSEC-2026-3948

Affected Products

Gitpython
Red Os