PT-2026-71448 · Pypi+1 · Gitpython+1
CVE-2026-73620
·
Published
2026-07-26
·
Updated
2026-09-03
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.57
Description
Insufficient guarding of git option forwarding in the
IndexFile.checkout() and TagReference.create() functions allows attackers to pass unsafe options via kwargs. This can be exploited using the --prefix option to overwrite arbitrary files with repository content or the -F option to read arbitrary files returned in-band.Recommendations
Update GitPython to version 3.1.57 or later.
Exploit
Fix
DoS
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os