{"schema_version":1,"title":"GitPython vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in GitPython: 1 in the last 7 days and 23 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100689, was published on 26 September 2026.","url":"https://junglewise.ai/threats/vendors/gitpython","json_url":"https://junglewise.ai/threats/vendors/gitpython.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/gitpython","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":14,"all_time":24,"critical":2,"exploited":0,"last_7_days":1,"last_30_days":1,"last_90_days":23,"last_365_days":23},"latest":[{"cve":"CVE-2026-100689","cvss":5.9,"slug":"cve-2026-100689-gitpython-before-3-1-62-does-not-validate-the-path-field-read","title":"GitPython path traversal in .gitmodules submodule update","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:53.42+00:00","url":"https://junglewise.ai/threats/cve-2026-100689-gitpython-before-3-1-62-does-not-validate-the-path-field-read"},{"cvss":6.5,"slug":"gitpython-incomplete-denylist-argument-injection-in-repo-blame-0f5a1996","title":"GitPython incomplete denylist argument injection in Repo.blame()","severity":"medium","exploited":false,"published_at":"2026-08-25T03:32:11+00:00","url":"https://junglewise.ai/threats/gitpython-incomplete-denylist-argument-injection-in-repo-blame-0f5a1996"},{"cvss":8.4,"slug":"gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0","title":"GitPython local file disclosure via .gitmodules include directive","severity":"high","exploited":false,"published_at":"2026-08-25T03:32:10+00:00","url":"https://junglewise.ai/threats/gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0"},{"cvss":7.5,"slug":"gitpython-path-traversal-in-clone-from-and-clone-via-separate-git-dir-76bb0c2e","title":"GitPython path traversal in clone_from() and clone() via --separate-git-dir","severity":"high","exploited":false,"published_at":"2026-08-25T03:32:10+00:00","url":"https://junglewise.ai/threats/gitpython-path-traversal-in-clone-from-and-clone-via-separate-git-dir-76bb0c2e"},{"cve":"CVE-2026-78679","cvss":6.5,"epss":0.0026,"slug":"cve-2026-78679-gitpython-tagreference-create-argument-injection-bypasses-file","title":"GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypass","severity":"medium","exploited":false,"published_at":"2026-08-25T02:16:52.47+00:00","url":"https://junglewise.ai/threats/cve-2026-78679-gitpython-tagreference-create-argument-injection-bypasses-file"},{"cve":"CVE-2026-78678","cvss":6.5,"epss":0.0041,"slug":"cve-2026-78678-gitpython-arbitrary-file-read-in-repo-blame-via-incomplete-option","title":"GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S option","severity":"medium","exploited":false,"published_at":"2026-08-25T02:16:52.313+00:00","url":"https://junglewise.ai/threats/cve-2026-78678-gitpython-arbitrary-file-read-in-repo-blame-via-incomplete-option"},{"cve":"CVE-2026-78677","cvss":7.5,"epss":0.0065,"slug":"cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist","title":"GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outsi","severity":"high","exploited":false,"published_at":"2026-08-25T02:16:52.173+00:00","url":"https://junglewise.ai/threats/cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist"},{"cvss":7.5,"slug":"gitpython-repo-init-argument-injection-via-template-8149779a","title":"GitPython Repo.init argument injection via --template","severity":"high","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-repo-init-argument-injection-via-template-8149779a"},{"cvss":3.1,"slug":"gitpython-argument-injection-in-repo-init-via-template-option-a9421bcb","title":"GitPython argument injection in Repo.init via --template option","severity":"low","exploited":false,"published_at":"2026-08-19T15:32:33+00:00","url":"https://junglewise.ai/threats/gitpython-argument-injection-in-repo-init-via-template-option-a9421bcb"},{"cve":"CVE-2026-73625","cvss":8.8,"epss":0.0092,"slug":"cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass","title":"GitPython remote code execution in option guard bypass","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.753+00:00","url":"https://junglewise.ai/threats/cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass"},{"cve":"CVE-2026-73624","cvss":8.1,"epss":0.005,"slug":"cve-2026-73624-gitpython-arbitrary-file-overwrite-in-diffable-diff","title":"GitPython arbitrary file overwrite in Diffable.diff","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.617+00:00","url":"https://junglewise.ai/threats/cve-2026-73624-gitpython-arbitrary-file-overwrite-in-diffable-diff"},{"cve":"CVE-2026-73623","cvss":7.5,"epss":0.0084,"slug":"cve-2026-73623-gitpython-unsafe-git-clone-options-incomplete-denylist-in","title":"GitPython unsafe_git_clone_options incomplete denylist in --template","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.477+00:00","url":"https://junglewise.ai/threats/cve-2026-73623-gitpython-unsafe-git-clone-options-incomplete-denylist-in"},{"cve":"CVE-2026-73622","cvss":7.5,"epss":0.0051,"slug":"cve-2026-73622-gitpython-environment-variable-expansion-in-remote-create-and","title":"GitPython environment variable expansion in Remote.create() and Submodule.add()","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.337+00:00","url":"https://junglewise.ai/threats/cve-2026-73622-gitpython-environment-variable-expansion-in-remote-create-and"},{"cve":"CVE-2026-73621","cvss":5.4,"epss":0.0036,"slug":"cve-2026-73621-gitpython-argument-injection-in-commit-count","title":"GitPython argument injection in Commit.count","severity":"medium","exploited":false,"published_at":"2026-08-13T12:17:27.2+00:00","url":"https://junglewise.ai/threats/cve-2026-73621-gitpython-argument-injection-in-commit-count"},{"cve":"CVE-2026-73620","cvss":8.1,"epss":0.0057,"slug":"cve-2026-73620-gitpython-unguarded-git-option-forwarding-in-indexfile-checkout","title":"GitPython unguarded git option forwarding in IndexFile.checkout() and TagReference.create()","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.057+00:00","url":"https://junglewise.ai/threats/cve-2026-73620-gitpython-unguarded-git-option-forwarding-in-indexfile-checkout"},{"cve":"CVE-2026-73619","cvss":6.5,"epss":0.0041,"slug":"cve-2026-73619-gitpython-incomplete-denylist-in-repo-archive-allows-arbitrary","title":"GitPython incomplete denylist in Repo.archive allows arbitrary file read","severity":"medium","exploited":false,"published_at":"2026-08-13T12:17:26.913+00:00","url":"https://junglewise.ai/threats/cve-2026-73619-gitpython-incomplete-denylist-in-repo-archive-allows-arbitrary"},{"cvss":8.4,"slug":"gitpython-command-injection-via-unguarded-git-options-in-archive-and-ls-d903ac45","title":"GitPython command injection via unguarded Git options in archive and ls_remote","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-command-injection-via-unguarded-git-options-in-archive-and-ls-d903ac45"},{"cvss":7.5,"slug":"gitpython-environment-variable-exfiltration-in-repo-clone-from-7a5754b1","title":"GitPython environment-variable exfiltration in Repo.clone_from()","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-environment-variable-exfiltration-in-repo-clone-from-7a5754b1"},{"cvss":9.8,"slug":"gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b","title":"GitPython unsafe clone option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b"},{"cve":"CVE-2026-67326","cvss":7,"epss":0.0025,"slug":"cve-2026-67326-gitpython-newline-injection-in-config-writer-section-parameter","title":"GitPython newline injection in config_writer() section parameter","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:03.063+00:00","url":"https://junglewise.ai/threats/cve-2026-67326-gitpython-newline-injection-in-config-writer-section-parameter"},{"cve":"CVE-2026-67324","cvss":9.8,"epss":0.0064,"slug":"cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options","title":"GitPython unsafe option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T13:17:02.77+00:00","url":"https://junglewise.ai/threats/cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options"},{"cve":"CVE-2026-67323","cvss":8.4,"epss":0.0125,"slug":"cve-2026-67323-gitpython-command-injection-via-unguarded-git-options","title":"GitPython command injection via unguarded Git options","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:02.637+00:00","url":"https://junglewise.ai/threats/cve-2026-67323-gitpython-command-injection-via-unguarded-git-options"},{"cve":"CVE-2026-67322","cvss":7.5,"epss":0.0033,"slug":"cve-2026-67322-gitpython-environment-variable-exfiltration-in-repo-clone-from","title":"GitPython environment-variable exfiltration in Repo.clone_from()","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:02.493+00:00","url":"https://junglewise.ai/threats/cve-2026-67322-gitpython-environment-variable-exfiltration-in-repo-clone-from"},{"cve":"CVE-2024-22190","cvss":3.1,"epss":0.0032,"slug":"cve-2024-22190-gitpython-untrusted-search-path-code-execution-on-windows","title":"PYSEC-2024-4 - GitPython is a python library used to interact with Git repositories. There is an incomplete fix for . On Windows, GitPython u","severity":"low","exploited":false,"published_at":"2024-01-11T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-22190-gitpython-untrusted-search-path-code-execution-on-windows"}],"vendor":{"hub":true,"name":"GitPython","slug":"gitpython","description":"Python library for Git repository interaction and version control operations.","url":"https://junglewise.ai/threats/vendors/gitpython"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":2,"exploited":0,"vulnerabilities":7},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-67324","cvss":9.8,"epss":0.0064,"slug":"cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options","title":"GitPython unsafe option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T13:17:02.77+00:00","url":"https://junglewise.ai/threats/cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options"},{"cvss":9.8,"slug":"gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b","title":"GitPython unsafe clone option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b"},{"cve":"CVE-2026-73625","cvss":8.8,"epss":0.0092,"slug":"cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass","title":"GitPython remote code execution in option guard bypass","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.753+00:00","url":"https://junglewise.ai/threats/cve-2026-73625-gitpython-remote-code-execution-in-option-guard-bypass"},{"cve":"CVE-2026-67323","cvss":8.4,"epss":0.0125,"slug":"cve-2026-67323-gitpython-command-injection-via-unguarded-git-options","title":"GitPython command injection via unguarded Git options","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:02.637+00:00","url":"https://junglewise.ai/threats/cve-2026-67323-gitpython-command-injection-via-unguarded-git-options"},{"cvss":8.4,"slug":"gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0","title":"GitPython local file disclosure via .gitmodules include directive","severity":"high","exploited":false,"published_at":"2026-08-25T03:32:10+00:00","url":"https://junglewise.ai/threats/gitpython-local-file-disclosure-via-gitmodules-include-directive-e93466b0"},{"cvss":8.4,"slug":"gitpython-command-injection-via-unguarded-git-options-in-archive-and-ls-d903ac45","title":"GitPython command injection via unguarded Git options in archive and ls_remote","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-command-injection-via-unguarded-git-options-in-archive-and-ls-d903ac45"},{"cve":"CVE-2026-73620","cvss":8.1,"epss":0.0057,"slug":"cve-2026-73620-gitpython-unguarded-git-option-forwarding-in-indexfile-checkout","title":"GitPython unguarded git option forwarding in IndexFile.checkout() and TagReference.create()","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.057+00:00","url":"https://junglewise.ai/threats/cve-2026-73620-gitpython-unguarded-git-option-forwarding-in-indexfile-checkout"},{"cve":"CVE-2026-73624","cvss":8.1,"epss":0.005,"slug":"cve-2026-73624-gitpython-arbitrary-file-overwrite-in-diffable-diff","title":"GitPython arbitrary file overwrite in Diffable.diff","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.617+00:00","url":"https://junglewise.ai/threats/cve-2026-73624-gitpython-arbitrary-file-overwrite-in-diffable-diff"},{"cve":"CVE-2026-73623","cvss":7.5,"epss":0.0084,"slug":"cve-2026-73623-gitpython-unsafe-git-clone-options-incomplete-denylist-in","title":"GitPython unsafe_git_clone_options incomplete denylist in --template","severity":"high","exploited":false,"published_at":"2026-08-13T12:17:27.477+00:00","url":"https://junglewise.ai/threats/cve-2026-73623-gitpython-unsafe-git-clone-options-incomplete-denylist-in"},{"cve":"CVE-2026-78677","cvss":7.5,"epss":0.0065,"slug":"cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist","title":"GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outsi","severity":"high","exploited":false,"published_at":"2026-08-25T02:16:52.173+00:00","url":"https://junglewise.ai/threats/cve-2026-78677-gitpython-clone-from-omits-separate-git-dir-from-denylist"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[]}