gitpython project records
35 published records for vendor gitpython project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-73 External Control of File Name or Path3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
35 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2022-24439Proof of concept | Remote Code Execution (RCE)gitpython project · gitpython · CWE-20 | Critical9.8 | — | 5.7% | Dec 6, 2022 |
39Monitor | CVE-2023-40267No exploit | GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from.gitpython project · gitpython | Critical9.8 | — | 1.2% | Aug 11, 2023 |
39Monitor | CVE-2026-42284No exploit | GitPython: Unsafe option check validates multi_options before shlex.split transforms itgitpython project · gitpython · CWE-88 | Critical9.8 | — | 0.7% | May 7, 2026 |
37Monitor | CVE-2026-78676No exploit | GitPython before 3.1.59 Remote Code Execution via Config Injectiongitpython project · gitpython · CWE-88 | Critical9.3 | — | 0.8% | Aug 24, 2026 |
37Monitor | CVE-2026-67324No exploit | GitPython 3.1.50 Authentication Bypass via Joined Short Optionsgitpython project · gitpython · CWE-78 | Critical9.3 | — | 0.6% | Aug 1, 2026 |
35Monitor | CVE-2026-67325No exploit | GitPython before 3.1.51 Command Injection via option prefix abbreviationgitpython project · gitpython · CWE-78 | High8.7 | — | 2.2% | Aug 1, 2026 |
35Monitor | CVE-2026-42215No exploit | GitPython: Command injection via Git options bypassgitpython project · gitpython · CWE-78 | High8.8 | — | 0.9% | May 7, 2026 |
34Monitor | CVE-2026-67323No exploit | GitPython before 3.1.51 Command Injection via unguarded Git optionsgitpython project · gitpython · CWE-77 | High8.6 | — | 1.3% | Aug 1, 2026 |
34Monitor | CVE-2026-73625No exploit | GitPython before 3.1.54 Remote Code Execution via kwarg value smugglinggitpython project · gitpython · CWE-78 | High8.7 | — | 0.9% | Aug 13, 2026 |
34Monitor | CVE-2026-76220No exploit | GitPython before 3.1.58 Command Execution via split_single_char_optionsgitpython project · gitpython · CWE-88 | High8.7 | — | 0.9% | Aug 19, 2026 |
34Monitor | CVE-2026-76221No exploit | GitPython before 3.1.58 Config Injection via option-namegitpython project · gitpython · CWE-74 | High8.7 | — | 0.8% | Aug 19, 2026 |
34Monitor | CVE-2026-78677No exploit | GitPython before 3.1.59 Path Traversal via separate-git-dirgitpython project · gitpython · CWE-22 | High8.7 | — | 0.7% | Aug 24, 2026 |
34Monitor | CVE-2026-87819No exploit | GitPython before 3.1.60 Denial of Service via ReDoSgitpython project · gitpython · CWE-1333 | High8.7 | — | 0.5% | Sep 9, 2026 |
34Monitor | CVE-2026-73622No exploit | GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()gitpython project · gitpython · CWE-200 | High8.7 | — | 0.5% | Aug 13, 2026 |
34Monitor | CVE-2026-87817No exploit | GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonationgitpython project · gitpython · CWE-94 | High8.7 | — | 0.4% | Sep 9, 2026 |
34Monitor | CVE-2026-67322No exploit | GitPython before 3.1.52 Environment Variable Exfiltration via clone_fromgitpython project · gitpython · CWE-200 | High8.7 | — | 0.3% | Aug 1, 2026 |
34Monitor | CVE-2026-78675No exploit | GitPython before 3.1.59 Local File Content Disclosure via .gitmodulesgitpython project · gitpython · CWE-73 | High8.6 | — | 0.2% | Aug 24, 2026 |
33Monitor | CVE-2026-76222No exploit | GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Namegitpython project · gitpython · CWE-22 | High8.4 | — | 0.4% | Aug 19, 2026 |
31Monitor | CVE-2023-40590No exploit | Untrusted search path on Windows systems leading to arbitrary code executiongitpython project · gitpython · CWE-426 | High7.8 | — | 0.5% | Aug 28, 2023 |
31Monitor | CVE-2026-44243No exploit | GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repositorygitpython project · gitpython · CWE-22 | High7.8 | — | 0.4% | May 7, 2026 |
31Monitor | CVE-2024-22190No exploit | Untrusted search path under some conditions on Windows allows arbitrary code executiongitpython project · gitpython · CWE-426 | High7.8 | — | 0.3% | Jan 10, 2024 |
31Monitor | CVE-2026-44244No exploit | GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathgitpython project · gitpython · CWE-94 | High7.8 | — | 0.2% | May 7, 2026 |
30Monitor | CVE-2026-73623No exploit | GitPython before 3.1.54 Remote Code Execution via --templategitpython project · gitpython · CWE-78 | High7.7 | — | 0.8% | Aug 13, 2026 |
30Monitor | CVE-2026-76218No exploit | GitPython before 3.1.58 Remote Code Execution via Repo.initgitpython project · gitpython · CWE-88 | High7.7 | — | 0.8% | Aug 19, 2026 |
29Monitor | CVE-2026-69097No exploit | GitPython before 3.1.53 Config Injection via Submodule Namesgitpython project · gitpython · CWE-74 | High7.3 | — | 0.3% | Aug 3, 2026 |
- CVE-2022-2443941Plan
Remote Code Execution (RCE)
CriticalCVSS 9.8Proof of conceptEPSS 6%gitpython project · gitpythonDec 6, 2022
- CVE-2023-4026739Monitor
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from.
CriticalCVSS 9.8No exploitEPSS 1%gitpython project · gitpythonAug 11, 2023
- CVE-2026-4228439Monitor
GitPython: Unsafe option check validates multi_options before shlex.split transforms it
CriticalCVSS 9.8No exploitEPSS 1%gitpython project · gitpythonMay 7, 2026
- CVE-2026-7867637Monitor
GitPython before 3.1.59 Remote Code Execution via Config Injection
CriticalCVSS 9.3No exploitEPSS 1%gitpython project · gitpythonAug 24, 2026
- CVE-2026-6732437Monitor
GitPython 3.1.50 Authentication Bypass via Joined Short Options
CriticalCVSS 9.3No exploitEPSS 1%gitpython project · gitpythonAug 1, 2026
- CVE-2026-6732535Monitor
GitPython before 3.1.51 Command Injection via option prefix abbreviation
HighCVSS 8.7No exploitEPSS 2%gitpython project · gitpythonAug 1, 2026
- CVE-2026-4221535Monitor
GitPython: Command injection via Git options bypass
HighCVSS 8.8No exploitEPSS 1%gitpython project · gitpythonMay 7, 2026
- CVE-2026-6732334Monitor
GitPython before 3.1.51 Command Injection via unguarded Git options
HighCVSS 8.6No exploitEPSS 1%gitpython project · gitpythonAug 1, 2026
- CVE-2026-7362534Monitor
GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling
HighCVSS 8.7No exploitEPSS 1%gitpython project · gitpythonAug 13, 2026
- CVE-2026-7622034Monitor
GitPython before 3.1.58 Command Execution via split_single_char_options
HighCVSS 8.7No exploitEPSS 1%gitpython project · gitpythonAug 19, 2026
- CVE-2026-7622134Monitor
GitPython before 3.1.58 Config Injection via option-name
HighCVSS 8.7No exploitEPSS 1%gitpython project · gitpythonAug 19, 2026
- CVE-2026-7867734Monitor
GitPython before 3.1.59 Path Traversal via separate-git-dir
HighCVSS 8.7No exploitEPSS 1%gitpython project · gitpythonAug 24, 2026
- CVE-2026-8781934Monitor
GitPython before 3.1.60 Denial of Service via ReDoS
HighCVSS 8.7No exploitEPSS 1%gitpython project · gitpythonSep 9, 2026
- CVE-2026-7362234Monitor
GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()
HighCVSS 8.7No exploitEPSS 1%gitpython project · gitpythonAug 13, 2026
- CVE-2026-8781734Monitor
GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation
HighCVSS 8.7No exploitEPSS 0%gitpython project · gitpythonSep 9, 2026
- CVE-2026-6732234Monitor
GitPython before 3.1.52 Environment Variable Exfiltration via clone_from
HighCVSS 8.7No exploitEPSS 0%gitpython project · gitpythonAug 1, 2026
- CVE-2026-7867534Monitor
GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
HighCVSS 8.6No exploitEPSS 0%gitpython project · gitpythonAug 24, 2026
- CVE-2026-7622233Monitor
GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name
HighCVSS 8.4No exploitEPSS 0%gitpython project · gitpythonAug 19, 2026
- CVE-2023-4059031Monitor
Untrusted search path on Windows systems leading to arbitrary code execution
HighCVSS 7.8No exploitEPSS 1%gitpython project · gitpythonAug 28, 2023
- CVE-2026-4424331Monitor
GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository
HighCVSS 7.8No exploitEPSS 0%gitpython project · gitpythonMay 7, 2026
- CVE-2024-2219031Monitor
Untrusted search path under some conditions on Windows allows arbitrary code execution
HighCVSS 7.8No exploitEPSS 0%gitpython project · gitpythonJan 10, 2024
- CVE-2026-4424431Monitor
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
HighCVSS 7.8No exploitEPSS 0%gitpython project · gitpythonMay 7, 2026
- CVE-2026-7362330Monitor
GitPython before 3.1.54 Remote Code Execution via --template
HighCVSS 7.7No exploitEPSS 1%gitpython project · gitpythonAug 13, 2026
- CVE-2026-7621830Monitor
GitPython before 3.1.58 Remote Code Execution via Repo.init
HighCVSS 7.7No exploitEPSS 1%gitpython project · gitpythonAug 19, 2026
- CVE-2026-6909729Monitor
GitPython before 3.1.53 Config Injection via Submodule Names
HighCVSS 7.3No exploitEPSS 0%gitpython project · gitpythonAug 3, 2026