PT-2026-78399 · Pypi+1 · Gitpython+1

·

CVE-2026-76217

·

Published

2026-08-07

·

Updated

2026-09-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.58
Description Insufficient validation of options passed to the git rm and git checkout commands within the IndexFile.remove() and Head.checkout() functions allows for arbitrary file reading. An attacker can provide the --pathspec-from-file and --pathspec-file-nul parameters to access files readable by the process, with the contents returned in GitCommandError.stderr.
Recommendations Update GitPython to version 3.1.58 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76217
GHSA-HH9P-6WH2-4MFC
GHSA-W672-239G-C3GR
OESA-2026-3523
OESA-2026-3524
OPENSUSE-SU-2026:11566-1
PYSEC-2026-3841

Affected Products

Gitpython
Red Os