PT-2026-81154 · Pypi · Gitpython
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.59
Description
An arbitrary file read issue exists in the
TagReference.create() function. A positional reference parameter allows the bypass of the unsafe option guard, enabling attackers to provide a reference value such as --file=<path> to read arbitrary files. The contents of the accessed files are then returned within the annotated tag message.Recommendations
Update GitPython to version 3.1.59 or later.
Exploit
Fix
Information Disclosure
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython