PT-2026-78399 · Pypi+1 · Gitpython+1
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.58
Description
Insufficient validation of options passed to the
git rm and git checkout commands within the IndexFile.remove() and Head.checkout() functions allows for arbitrary file reading. An attacker can provide the --pathspec-from-file and --pathspec-file-nul parameters to access files readable by the process, with the contents returned in GitCommandError.stderr.Recommendations
Update GitPython to version 3.1.58 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os