PT-2026-71448 · Pypi+1 · Gitpython+1

CVE-2026-73620

·

Published

2026-07-26

·

Updated

2026-09-03

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.57
Description Insufficient guarding of git option forwarding in the IndexFile.checkout() and TagReference.create() functions allows attackers to pass unsafe options via kwargs. This can be exploited using the --prefix option to overwrite arbitrary files with repository content or the -F option to read arbitrary files returned in-band.
Recommendations Update GitPython to version 3.1.57 or later.

Exploit

Fix

DoS

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11719
CVE-2026-73620
GHSA-3F7W-8RR8-F37F
OPENSUSE-SU-2026:11566-1
PYSEC-2026-3949

Affected Products

Gitpython
Red Os