PT-2026-81154 · Pypi · Gitpython

·

CVE-2026-78679

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.59
Description An arbitrary file read issue exists in the TagReference.create() function. A positional reference parameter allows the bypass of the unsafe option guard, enabling attackers to provide a reference value such as --file=<path> to read arbitrary files. The contents of the accessed files are then returned within the annotated tag message.
Recommendations Update GitPython to version 3.1.59 or later.

Exploit

Fix

Information Disclosure

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78679
GHSA-3WXW-XV34-2FRG
GHSA-6RJ2-96F5-CHJ9
OPENSUSE-SU-2026:11615-1
PYSEC-2026-3837

Affected Products

Gitpython