{"schema_version":1,"title":"Gitpython Project Gitpython vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 56 vulnerabilities in Gitpython Project Gitpython: 0 in the last 7 days and 52 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-87819, was published on 9 September 2026.","url":"https://junglewise.ai/threats/technologies/gitpython","json_url":"https://junglewise.ai/threats/technologies/gitpython.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gitpython","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":40,"all_time":56,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":52,"last_365_days":55},"latest":[{"cve":"CVE-2026-87819","cvss":7.5,"epss":0.0052,"slug":"cve-2026-87819-gitpython-redos-via-catastrophic-backtracking-in-actor-name-email","title":"GitPython ReDoS via catastrophic backtracking in Actor.name_email_regex","severity":"high","exploited":false,"published_at":"2026-09-09T12:17:17.12+00:00","url":"https://junglewise.ai/threats/cve-2026-87819-gitpython-redos-via-catastrophic-backtracking-in-actor-name-email"},{"cve":"CVE-2026-87818","cvss":6.5,"epss":0.0041,"slug":"cve-2026-87818-gitpython-argument-injection-in-diff-api-via-no-index","title":"GitPython argument injection in diff API via --no-index","severity":"medium","exploited":false,"published_at":"2026-09-09T12:17:16.98+00:00","url":"https://junglewise.ai/threats/cve-2026-87818-gitpython-argument-injection-in-diff-api-via-no-index"},{"cve":"CVE-2026-87817","cvss":8.8,"epss":0.0041,"slug":"cve-2026-87817-gitpython-git-directory-impersonation-leading-to-code-execution","title":"GitPython git directory impersonation leading to code execution","severity":"high","exploited":false,"published_at":"2026-09-09T12:17:16.83+00:00","url":"https://junglewise.ai/threats/cve-2026-87817-gitpython-git-directory-impersonation-leading-to-code-execution"},{"cvss":6.5,"slug":"gitpython-incomplete-denylist-argument-injection-in-repo-blame-0f5a1996","title":"GitPython incomplete denylist argument injection in Repo.blame()","severity":"medium","exploited":false,"published_at":"2026-08-25T03:32:11+00:00","url":"https://junglewise.ai/threats/gitpython-incomplete-denylist-argument-injection-in-repo-blame-0f5a1996"},{"cvss":6.5,"slug":"gitpython-tagreference-create-arbitrary-file-read-via-positional-4b3f134a","title":"GitPython TagReference.create arbitrary file read via positional argument injection","severity":"medium","exploited":false,"published_at":"2026-08-25T03:32:11+00:00","url":"https://junglewise.ai/threats/gitpython-tagreference-create-arbitrary-file-read-via-positional-4b3f134a"},{"cvss":8.4,"slug":"gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0","title":"GitPython local file disclosure via .gitmodules include directive","severity":"high","exploited":false,"published_at":"2026-08-25T03:32:10+00:00","url":"https://junglewise.ai/threats/gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0"},{"cvss":7.5,"slug":"gitpython-path-traversal-in-clone-from-and-clone-via-separate-git-dir-76bb0c2e","title":"GitPython path traversal in clone_from() and clone() via --separate-git-dir","severity":"high","exploited":false,"published_at":"2026-08-25T03:32:10+00:00","url":"https://junglewise.ai/threats/gitpython-path-traversal-in-clone-from-and-clone-via-separate-git-dir-76bb0c2e"},{"cve":"CVE-2026-78679","cvss":6.5,"epss":0.0026,"slug":"cve-2026-78679-gitpython-tagreference-create-argument-injection-bypasses-file","title":"GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypass","severity":"medium","exploited":false,"published_at":"2026-08-25T02:16:52.47+00:00","url":"https://junglewise.ai/threats/cve-2026-78679-gitpython-tagreference-create-argument-injection-bypasses-file"},{"cve":"CVE-2026-78678","cvss":6.5,"epss":0.0041,"slug":"cve-2026-78678-gitpython-arbitrary-file-read-in-repo-blame-via-incomplete-option","title":"GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S option","severity":"medium","exploited":false,"published_at":"2026-08-25T02:16:52.313+00:00","url":"https://junglewise.ai/threats/cve-2026-78678-gitpython-arbitrary-file-read-in-repo-blame-via-incomplete-option"},{"cve":"CVE-2026-78677","cvss":7.5,"epss":0.0065,"slug":"cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist","title":"GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outsi","severity":"high","exploited":false,"published_at":"2026-08-25T02:16:52.173+00:00","url":"https://junglewise.ai/threats/cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist"},{"cve":"CVE-2026-78676","cvss":9.8,"epss":0.0078,"slug":"cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write","title":"GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values","severity":"critical","exploited":false,"published_at":"2026-08-25T02:16:52.03+00:00","url":"https://junglewise.ai/threats/cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write"},{"cve":"CVE-2026-78675","cvss":8.4,"epss":0.0018,"slug":"cve-2026-78675-gitpython-arbitrary-local-file-content-disclosure-via-gitmodules","title":"GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by inclu","severity":"high","exploited":false,"published_at":"2026-08-25T02:16:51.887+00:00","url":"https://junglewise.ai/threats/cve-2026-78675-gitpython-arbitrary-local-file-content-disclosure-via-gitmodules"},{"cvss":7.5,"slug":"gitpython-repo-init-argument-injection-via-template-8149779a","title":"GitPython Repo.init argument injection via --template","severity":"high","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-repo-init-argument-injection-via-template-8149779a"},{"cvss":8.1,"slug":"gitpython-arbitrary-file-overwrite-in-indexfile-from-tree-reset-merge-d7d8520f","title":"GitPython arbitrary file overwrite in IndexFile.from_tree/reset/merge_tree","severity":"high","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-arbitrary-file-overwrite-in-indexfile-from-tree-reset-merge-d7d8520f"},{"cvss":8.8,"slug":"gitpython-command-execution-via-split-single-char-options-guard-bypass-395b0b32","title":"GitPython command execution via split_single_char_options guard bypass","severity":"high","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-command-execution-via-split-single-char-options-guard-bypass-395b0b32"},{"cvss":6.5,"slug":"gitpython-arbitrary-file-read-via-pathspec-parameters-e75ef8d9","title":"GitPython arbitrary file read via pathspec parameters","severity":"medium","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-arbitrary-file-read-via-pathspec-parameters-e75ef8d9"},{"cvss":8.2,"slug":"gitpython-path-traversal-via-unvalidated-gitmodules-submodule-name-d3186e91","title":"GitPython path traversal via unvalidated .gitmodules submodule name","severity":"high","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-path-traversal-via-unvalidated-gitmodules-submodule-name-d3186e91"},{"cvss":3.1,"slug":"gitpython-argument-injection-in-repo-init-via-template-option-a9421bcb","title":"GitPython argument injection in Repo.init via --template option","severity":"low","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-argument-injection-in-repo-init-via-template-option-a9421bcb"},{"cve":"CVE-2026-73625","cvss":8.8,"epss":0.0092,"slug":"cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass","title":"GitPython remote code execution in option guard bypass","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.753+00:00","url":"https://junglewise.ai/threats/cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass"},{"cve":"CVE-2026-73624","cvss":8.1,"epss":0.005,"slug":"cve-2026-73624-gitpython-arbitrary-file-overwrite-in-diffable-diff","title":"GitPython arbitrary file overwrite in Diffable.diff","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.617+00:00","url":"https://junglewise.ai/threats/cve-2026-73624-gitpython-arbitrary-file-overwrite-in-diffable-diff"},{"cve":"CVE-2026-73623","cvss":7.5,"epss":0.0084,"slug":"cve-2026-73623-gitpython-unsafe-git-clone-options-incomplete-denylist-in","title":"GitPython unsafe_git_clone_options incomplete denylist in --template","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.477+00:00","url":"https://junglewise.ai/threats/cve-2026-73623-gitpython-unsafe-git-clone-options-incomplete-denylist-in"},{"cve":"CVE-2026-73622","cvss":7.5,"epss":0.0051,"slug":"cve-2026-73622-gitpython-environment-variable-expansion-in-remote-create-and","title":"GitPython environment variable expansion in Remote.create() and Submodule.add()","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.337+00:00","url":"https://junglewise.ai/threats/cve-2026-73622-gitpython-environment-variable-expansion-in-remote-create-and"},{"cve":"CVE-2026-73621","cvss":5.4,"epss":0.0036,"slug":"cve-2026-73621-gitpython-argument-injection-in-commit-count","title":"GitPython argument injection in Commit.count","severity":"medium","exploited":false,"published_at":"2026-08-13T12:17:27.2+00:00","url":"https://junglewise.ai/threats/cve-2026-73621-gitpython-argument-injection-in-commit-count"},{"cve":"CVE-2026-73620","cvss":8.1,"epss":0.0057,"slug":"cve-2026-73620-gitpython-unguarded-git-option-forwarding-in-indexfile-checkout","title":"GitPython unguarded git option forwarding in IndexFile.checkout() and TagReference.create()","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.057+00:00","url":"https://junglewise.ai/threats/cve-2026-73620-gitpython-unguarded-git-option-forwarding-in-indexfile-checkout"},{"cve":"CVE-2026-73619","cvss":6.5,"epss":0.0041,"slug":"cve-2026-73619-gitpython-incomplete-denylist-in-repo-archive-allows-arbitrary","title":"GitPython incomplete denylist in Repo.archive allows arbitrary file read","severity":"medium","exploited":false,"published_at":"2026-08-13T12:17:26.913+00:00","url":"https://junglewise.ai/threats/cve-2026-73619-gitpython-incomplete-denylist-in-repo-archive-allows-arbitrary"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-27","critical":2,"exploited":0,"vulnerabilities":9},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":9},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Gitpython Project Gitpython","slug":"gitpython","vendor":{"name":"Gitpython Project","slug":"gitpython-project","url":"https://junglewise.ai/threats/vendors/gitpython-project"},"aliases":[],"category":"library","description":"Python library for interacting with Git repositories.","url":"https://junglewise.ai/threats/technologies/gitpython"},"most_severe":[{"cve":"CVE-2026-78676","cvss":9.8,"epss":0.0078,"slug":"cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write","title":"GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values","severity":"critical","exploited":false,"published_at":"2026-08-25T02:16:52.03+00:00","url":"https://junglewise.ai/threats/cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write"},{"cve":"CVE-2026-67324","cvss":9.8,"epss":0.0064,"slug":"cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options","title":"GitPython unsafe option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T13:17:02.77+00:00","url":"https://junglewise.ai/threats/cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options"},{"cvss":9.8,"slug":"gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b","title":"GitPython unsafe clone option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b"},{"cve":"CVE-2026-67325","cvss":8.8,"epss":0.0221,"slug":"cve-2026-67325-gitpython-command-injection-via-option-prefix-abbreviation","title":"GitPython command injection via option prefix abbreviation","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:02.923+00:00","url":"https://junglewise.ai/threats/cve-2026-67325-gitpython-command-injection-via-option-prefix-abbreviation"},{"cve":"CVE-2026-73625","cvss":8.8,"epss":0.0092,"slug":"cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass","title":"GitPython remote code execution in option guard bypass","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.753+00:00","url":"https://junglewise.ai/threats/cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass"},{"cve":"CVE-2026-42215","cvss":8.8,"epss":0.009,"slug":"cve-2026-42215-gitpython-command-injection-via-keyword-argument-bypass","title":"GitPython command injection via keyword argument bypass","severity":"high","exploited":false,"published_at":"2026-05-07T19:16:01.64+00:00","url":"https://junglewise.ai/threats/cve-2026-42215-gitpython-command-injection-via-keyword-argument-bypass"},{"cve":"CVE-2026-87817","cvss":8.8,"epss":0.0041,"slug":"cve-2026-87817-gitpython-git-directory-impersonation-leading-to-code-execution","title":"GitPython git directory impersonation leading to code execution","severity":"high","exploited":false,"published_at":"2026-09-09T12:17:16.83+00:00","url":"https://junglewise.ai/threats/cve-2026-87817-gitpython-git-directory-impersonation-leading-to-code-execution"},{"cvss":8.8,"slug":"gitpython-command-execution-via-split-single-char-options-guard-bypass-395b0b32","title":"GitPython command execution via split_single_char_options guard bypass","severity":"high","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-command-execution-via-split-single-char-options-guard-bypass-395b0b32"},{"cvss":8.8,"slug":"gitpython-command-execution-via-short-option-smuggling-bypass-37730e44","title":"GitPython command execution via short-option smuggling bypass","severity":"high","exploited":false,"published_at":"2026-08-07T15:49:07+00:00","url":"https://junglewise.ai/threats/gitpython-command-execution-via-short-option-smuggling-bypass-37730e44"},{"cvss":8.8,"slug":"gitpython-rce-via-git-config-option-name-injection-a2291ba6","title":"GitPython RCE via git-config option name injection","severity":"high","exploited":false,"published_at":"2026-08-07T15:46:35+00:00","url":"https://junglewise.ai/threats/gitpython-rce-via-git-config-option-name-injection-a2291ba6"}],"generated_at":"2026-09-26T11:07:00.153785+00:00"}