PT-2026-71453 · Pypi+1 · Gitpython+1
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.54
Description
A remote code execution issue exists in the
check unsafe options guard. This guard can be bypassed by smuggling git options within single-character kwarg values. An attacker can provide crafted option dictionaries to the clone from, fetch, pull, push, ls remote, iter commits, blame, or archive methods to execute arbitrary OS commands using the --upload-pack parameter.Recommendations
Update GitPython to version 3.1.54 or later.
Exploit
Fix
RCE
OS Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os