Executive brief
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Affected products
- PyPI gitpython
Junglewise Threat Intelligence
CVE-2026-76217 · Severity: low · CVSS 3.1 · Published 2026-09-10
Vendors: PyPI.
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()