PT-2026-71452 · Pypi · Gitpython
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.54
Description
An arbitrary file overwrite issue exists in the
Diffable.diff() method due to insufficient validation of git options passed through kwargs. An attacker can use the --output argument via the other parameter or output kwarg to write patch content to files at paths of their choosing, operating at the privilege level of the process.Recommendations
Update GitPython to version 3.1.54 or later.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitpython