Записи gitpython project
35 опубликованных записей вендора gitpython project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-73 External Control of File Name or Path3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
35 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2022-24439Proof of concept | Remote Code Execution (RCE)gitpython project · gitpython · CWE-20 | Критическая9,8 | — | 5,7 % | 6 дек. 2022 г. |
39Наблюдать | CVE-2023-40267Эксплойта нет | GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from.gitpython project · gitpython | Критическая9,8 | — | 1,2 % | 11 авг. 2023 г. |
39Наблюдать | CVE-2026-42284Эксплойта нет | GitPython: Unsafe option check validates multi_options before shlex.split transforms itgitpython project · gitpython · CWE-88 | Критическая9,8 | — | 0,7 % | 7 мая 2026 г. |
37Наблюдать | CVE-2026-78676Эксплойта нет | GitPython before 3.1.59 Remote Code Execution via Config Injectiongitpython project · gitpython · CWE-88 | Критическая9,3 | — | 0,8 % | 24 авг. 2026 г. |
37Наблюдать | CVE-2026-67324Эксплойта нет | GitPython 3.1.50 Authentication Bypass via Joined Short Optionsgitpython project · gitpython · CWE-78 | Критическая9,3 | — | 0,6 % | 1 авг. 2026 г. |
35Наблюдать | CVE-2026-67325Эксплойта нет | GitPython before 3.1.51 Command Injection via option prefix abbreviationgitpython project · gitpython · CWE-78 | Высокая8,7 | — | 2,2 % | 1 авг. 2026 г. |
35Наблюдать | CVE-2026-42215Эксплойта нет | GitPython: Command injection via Git options bypassgitpython project · gitpython · CWE-78 | Высокая8,8 | — | 0,9 % | 7 мая 2026 г. |
34Наблюдать | CVE-2026-67323Эксплойта нет | GitPython before 3.1.51 Command Injection via unguarded Git optionsgitpython project · gitpython · CWE-77 | Высокая8,6 | — | 1,3 % | 1 авг. 2026 г. |
34Наблюдать | CVE-2026-73625Эксплойта нет | GitPython before 3.1.54 Remote Code Execution via kwarg value smugglinggitpython project · gitpython · CWE-78 | Высокая8,7 | — | 0,9 % | 13 авг. 2026 г. |
34Наблюдать | CVE-2026-76220Эксплойта нет | GitPython before 3.1.58 Command Execution via split_single_char_optionsgitpython project · gitpython · CWE-88 | Высокая8,7 | — | 0,9 % | 19 авг. 2026 г. |
34Наблюдать | CVE-2026-76221Эксплойта нет | GitPython before 3.1.58 Config Injection via option-namegitpython project · gitpython · CWE-74 | Высокая8,7 | — | 0,8 % | 19 авг. 2026 г. |
34Наблюдать | CVE-2026-78677Эксплойта нет | GitPython before 3.1.59 Path Traversal via separate-git-dirgitpython project · gitpython · CWE-22 | Высокая8,7 | — | 0,7 % | 24 авг. 2026 г. |
34Наблюдать | CVE-2026-87819Эксплойта нет | GitPython before 3.1.60 Denial of Service via ReDoSgitpython project · gitpython · CWE-1333 | Высокая8,7 | — | 0,5 % | 9 сент. 2026 г. |
34Наблюдать | CVE-2026-73622Эксплойта нет | GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()gitpython project · gitpython · CWE-200 | Высокая8,7 | — | 0,5 % | 13 авг. 2026 г. |
34Наблюдать | CVE-2026-87817Эксплойта нет | GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonationgitpython project · gitpython · CWE-94 | Высокая8,7 | — | 0,4 % | 9 сент. 2026 г. |
34Наблюдать | CVE-2026-67322Эксплойта нет | GitPython before 3.1.52 Environment Variable Exfiltration via clone_fromgitpython project · gitpython · CWE-200 | Высокая8,7 | — | 0,3 % | 1 авг. 2026 г. |
34Наблюдать | CVE-2026-78675Эксплойта нет | GitPython before 3.1.59 Local File Content Disclosure via .gitmodulesgitpython project · gitpython · CWE-73 | Высокая8,6 | — | 0,2 % | 24 авг. 2026 г. |
33Наблюдать | CVE-2026-76222Эксплойта нет | GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Namegitpython project · gitpython · CWE-22 | Высокая8,4 | — | 0,4 % | 19 авг. 2026 г. |
31Наблюдать | CVE-2023-40590Эксплойта нет | Untrusted search path on Windows systems leading to arbitrary code executiongitpython project · gitpython · CWE-426 | Высокая7,8 | — | 0,5 % | 28 авг. 2023 г. |
31Наблюдать | CVE-2026-44243Эксплойта нет | GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repositorygitpython project · gitpython · CWE-22 | Высокая7,8 | — | 0,4 % | 7 мая 2026 г. |
31Наблюдать | CVE-2024-22190Эксплойта нет | Untrusted search path under some conditions on Windows allows arbitrary code executiongitpython project · gitpython · CWE-426 | Высокая7,8 | — | 0,3 % | 10 янв. 2024 г. |
31Наблюдать | CVE-2026-44244Эксплойта нет | GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathgitpython project · gitpython · CWE-94 | Высокая7,8 | — | 0,2 % | 7 мая 2026 г. |
30Наблюдать | CVE-2026-73623Эксплойта нет | GitPython before 3.1.54 Remote Code Execution via --templategitpython project · gitpython · CWE-78 | Высокая7,7 | — | 0,8 % | 13 авг. 2026 г. |
30Наблюдать | CVE-2026-76218Эксплойта нет | GitPython before 3.1.58 Remote Code Execution via Repo.initgitpython project · gitpython · CWE-88 | Высокая7,7 | — | 0,8 % | 19 авг. 2026 г. |
29Наблюдать | CVE-2026-69097Эксплойта нет | GitPython before 3.1.53 Config Injection via Submodule Namesgitpython project · gitpython · CWE-74 | Высокая7,3 | — | 0,3 % | 3 авг. 2026 г. |
- CVE-2022-2443941В плане
Remote Code Execution (RCE)
КритическаяCVSS 9,8Proof of conceptEPSS 6 %gitpython project · gitpython6 дек. 2022 г.
- CVE-2023-4026739Наблюдать
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitpython project · gitpython11 авг. 2023 г.
- CVE-2026-4228439Наблюдать
GitPython: Unsafe option check validates multi_options before shlex.split transforms it
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gitpython project · gitpython7 мая 2026 г.
- CVE-2026-7867637Наблюдать
GitPython before 3.1.59 Remote Code Execution via Config Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %gitpython project · gitpython24 авг. 2026 г.
- CVE-2026-6732437Наблюдать
GitPython 3.1.50 Authentication Bypass via Joined Short Options
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %gitpython project · gitpython1 авг. 2026 г.
- CVE-2026-6732535Наблюдать
GitPython before 3.1.51 Command Injection via option prefix abbreviation
ВысокаяCVSS 8,7Эксплойта нетEPSS 2 %gitpython project · gitpython1 авг. 2026 г.
- CVE-2026-4221535Наблюдать
GitPython: Command injection via Git options bypass
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gitpython project · gitpython7 мая 2026 г.
- CVE-2026-6732334Наблюдать
GitPython before 3.1.51 Command Injection via unguarded Git options
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %gitpython project · gitpython1 авг. 2026 г.
- CVE-2026-7362534Наблюдать
GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %gitpython project · gitpython13 авг. 2026 г.
- CVE-2026-7622034Наблюдать
GitPython before 3.1.58 Command Execution via split_single_char_options
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %gitpython project · gitpython19 авг. 2026 г.
- CVE-2026-7622134Наблюдать
GitPython before 3.1.58 Config Injection via option-name
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %gitpython project · gitpython19 авг. 2026 г.
- CVE-2026-7867734Наблюдать
GitPython before 3.1.59 Path Traversal via separate-git-dir
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %gitpython project · gitpython24 авг. 2026 г.
- CVE-2026-8781934Наблюдать
GitPython before 3.1.60 Denial of Service via ReDoS
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %gitpython project · gitpython9 сент. 2026 г.
- CVE-2026-7362234Наблюдать
GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %gitpython project · gitpython13 авг. 2026 г.
- CVE-2026-8781734Наблюдать
GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %gitpython project · gitpython9 сент. 2026 г.
- CVE-2026-6732234Наблюдать
GitPython before 3.1.52 Environment Variable Exfiltration via clone_from
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %gitpython project · gitpython1 авг. 2026 г.
- CVE-2026-7867534Наблюдать
GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %gitpython project · gitpython24 авг. 2026 г.
- CVE-2026-7622233Наблюдать
GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %gitpython project · gitpython19 авг. 2026 г.
- CVE-2023-4059031Наблюдать
Untrusted search path on Windows systems leading to arbitrary code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gitpython project · gitpython28 авг. 2023 г.
- CVE-2026-4424331Наблюдать
GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gitpython project · gitpython7 мая 2026 г.
- CVE-2024-2219031Наблюдать
Untrusted search path under some conditions on Windows allows arbitrary code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gitpython project · gitpython10 янв. 2024 г.
- CVE-2026-4424431Наблюдать
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gitpython project · gitpython7 мая 2026 г.
- CVE-2026-7362330Наблюдать
GitPython before 3.1.54 Remote Code Execution via --template
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %gitpython project · gitpython13 авг. 2026 г.
- CVE-2026-7621830Наблюдать
GitPython before 3.1.58 Remote Code Execution via Repo.init
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %gitpython project · gitpython19 авг. 2026 г.
- CVE-2026-6909729Наблюдать
GitPython before 3.1.53 Config Injection via Submodule Names
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %gitpython project · gitpython3 авг. 2026 г.