Skip to content
Noroxi

gitpython project records

35 published records for vendor gitpython project.

All records

35 records
  • Remote Code Execution (RCE)

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    gitpython project · gitpythonDec 6, 2022

  • GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from.

    CriticalCVSS 9.8No exploitEPSS 1%

    gitpython project · gitpythonAug 11, 2023

  • GitPython: Unsafe option check validates multi_options before shlex.split transforms it

    CriticalCVSS 9.8No exploitEPSS 1%

    gitpython project · gitpythonMay 7, 2026

  • GitPython before 3.1.59 Remote Code Execution via Config Injection

    CriticalCVSS 9.3No exploitEPSS 1%

    gitpython project · gitpythonAug 24, 2026

  • GitPython 3.1.50 Authentication Bypass via Joined Short Options

    CriticalCVSS 9.3No exploitEPSS 1%

    gitpython project · gitpythonAug 1, 2026

  • GitPython before 3.1.51 Command Injection via option prefix abbreviation

    HighCVSS 8.7No exploitEPSS 2%

    gitpython project · gitpythonAug 1, 2026

  • GitPython: Command injection via Git options bypass

    HighCVSS 8.8No exploitEPSS 1%

    gitpython project · gitpythonMay 7, 2026

  • GitPython before 3.1.51 Command Injection via unguarded Git options

    HighCVSS 8.6No exploitEPSS 1%

    gitpython project · gitpythonAug 1, 2026

  • GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling

    HighCVSS 8.7No exploitEPSS 1%

    gitpython project · gitpythonAug 13, 2026

  • GitPython before 3.1.58 Command Execution via split_single_char_options

    HighCVSS 8.7No exploitEPSS 1%

    gitpython project · gitpythonAug 19, 2026

  • GitPython before 3.1.58 Config Injection via option-name

    HighCVSS 8.7No exploitEPSS 1%

    gitpython project · gitpythonAug 19, 2026

  • GitPython before 3.1.59 Path Traversal via separate-git-dir

    HighCVSS 8.7No exploitEPSS 1%

    gitpython project · gitpythonAug 24, 2026

  • GitPython before 3.1.60 Denial of Service via ReDoS

    HighCVSS 8.7No exploitEPSS 1%

    gitpython project · gitpythonSep 9, 2026

  • GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()

    HighCVSS 8.7No exploitEPSS 1%

    gitpython project · gitpythonAug 13, 2026

  • GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation

    HighCVSS 8.7No exploitEPSS 0%

    gitpython project · gitpythonSep 9, 2026

  • GitPython before 3.1.52 Environment Variable Exfiltration via clone_from

    HighCVSS 8.7No exploitEPSS 0%

    gitpython project · gitpythonAug 1, 2026

  • GitPython before 3.1.59 Local File Content Disclosure via .gitmodules

    HighCVSS 8.6No exploitEPSS 0%

    gitpython project · gitpythonAug 24, 2026

  • GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name

    HighCVSS 8.4No exploitEPSS 0%

    gitpython project · gitpythonAug 19, 2026

  • Untrusted search path on Windows systems leading to arbitrary code execution

    HighCVSS 7.8No exploitEPSS 1%

    gitpython project · gitpythonAug 28, 2023

  • GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository

    HighCVSS 7.8No exploitEPSS 0%

    gitpython project · gitpythonMay 7, 2026

  • Untrusted search path under some conditions on Windows allows arbitrary code execution

    HighCVSS 7.8No exploitEPSS 0%

    gitpython project · gitpythonJan 10, 2024

  • GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

    HighCVSS 7.8No exploitEPSS 0%

    gitpython project · gitpythonMay 7, 2026

  • GitPython before 3.1.54 Remote Code Execution via --template

    HighCVSS 7.7No exploitEPSS 1%

    gitpython project · gitpythonAug 13, 2026

  • GitPython before 3.1.58 Remote Code Execution via Repo.init

    HighCVSS 7.7No exploitEPSS 1%

    gitpython project · gitpythonAug 19, 2026

  • GitPython before 3.1.53 Config Injection via Submodule Names

    HighCVSS 7.3No exploitEPSS 0%

    gitpython project · gitpythonAug 3, 2026