Security: gitpython-developers/GitPython
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)GHSA-7833-fr7j-v32q published
Aug 10, 2026 by ByronHigh -
Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCEGHSA-284h-m62q-gf8w published
Aug 10, 2026 by ByronHigh -
clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destinationGHSA-8mcc-hrx5-hvxc published
Aug 10, 2026 by ByronHigh -
Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()GHSA-5xxx-qhh7-9287 published
Aug 10, 2026 by ByronModerate -
TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)GHSA-3wxw-xv34-2frg published
Aug 10, 2026 by ByronModerate -
Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()GHSA-hh9p-6wh2-4mfc published
Aug 4, 2026 by ByronModerate -
Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooksGHSA-9rj7-rf2p-w77r published
Aug 4, 2026 by ByronHigh -
Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwriteGHSA-4gmw-gg2m-w46p published
Aug 4, 2026 by ByronHigh -
Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command executionGHSA-wvpp-8hx9-p66j published
Aug 4, 2026 by ByronHigh -
git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)GHSA-jm78-9fvv-mhgr published
Aug 4, 2026 by ByronHigh