PT-2026-71452 · Pypi · Gitpython

·

CVE-2026-73624

·

Published

2026-07-22

·

Updated

2026-08-21

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.54
Description An arbitrary file overwrite issue exists in the Diffable.diff() method due to insufficient validation of git options passed through kwargs. An attacker can use the --output argument via the other parameter or output kwarg to write patch content to files at paths of their choosing, operating at the privilege level of the process.
Recommendations Update GitPython to version 3.1.54 or later.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11882
CVE-2026-73624
GHSA-FJR4-X663-MWXC
OPENSUSE-SU-2026:11566-1

Affected Products

Gitpython