Security: gitpython-developers/GitPython
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()GHSA-hh9p-6wh2-4mfc published
Aug 4, 2026 by ByronModerate -
Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooksGHSA-9rj7-rf2p-w77r published
Aug 4, 2026 by ByronHigh -
Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwriteGHSA-4gmw-gg2m-w46p published
Aug 4, 2026 by ByronHigh -
Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command executionGHSA-wvpp-8hx9-p66j published
Aug 4, 2026 by ByronHigh -
git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)GHSA-jm78-9fvv-mhgr published
Aug 4, 2026 by ByronHigh -
Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPythonGHSA-hmq2-w58f-27jc published
Aug 4, 2026 by ByronHigh -
Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()GHSA-539m-9xh6-q6rr published
Jul 26, 2026 by ByronModerate -
Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file readGHSA-3f7w-8rr8-f37f published
Jul 26, 2026 by ByronHigh -
Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.countGHSA-p538-c434-8v24 published
Jul 25, 2026 by ByronModerate -
Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)GHSA-94p4-4cq8-9g67 published
Jul 23, 2026 by ByronHigh