Security: gitpython-developers/GitPython
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
separate_git_dir leaks env vars via crafted .gitmodules submodule nameGHSA-fx3j-rwgx-fr94 published
Sep 30, 2026 by ByronModerate -
Residual of GHSA-g5vv-9gxw-82hx: quadratic backtracking in _re_actor_epoch (parse_actor_and_date) on malformed author/committer/tagger linesGHSA-m64x-33q8-m5h7 published
Sep 30, 2026 by ByronModerate -
GitPython Remote.pull() refspec bypasses the --upload-pack unsafe-option guard, enabling arbitrary command executionGHSA-f9j4-qggq-h239 published
Sep 30, 2026 by ByronCritical -
GitPython: arbitrary file read via attacker-controlled branch name in `Head.checkout()` (incomplete fix of CVE-2026-78679, at the method named by CVE-2026-76217)GHSA-23mf-xhv8-69c2 published
Sep 30, 2026 by ByronHigh -
Submodule.move() follows an attacker-committed intermediate symlink outside the worktreeGHSA-gq48-pqfc-9p58 published
Sep 30, 2026 by ByronModerate -
Residual of GHSA-hmq2-w58f-27jc: the fix validates the `.gitmodules` **name** but the sibling **path** field still reaches `os.makedirs()` unguarded, although GitPython already owns the containment guardGHSA-59cr-6r3x-644w published
Sep 7, 2026 by ByronModerate -
Repository content can impersonate the git directory, leading to arbitrary code executionGHSA-239g-whfq-7xj9 published
Aug 26, 2026 by ByronHigh -
GitPython 3.1.59: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracleGHSA-whh4-5q6c-9v3x published
Aug 26, 2026 by ByronModerate -
Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsingGHSA-g5vv-9gxw-82hx published
Aug 26, 2026 by ByronHigh