Security: gitpython-developers/GitPython
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Repository content can impersonate the git directory, leading to arbitrary code executionGHSA-239g-whfq-7xj9 published
Aug 26, 2026 by ByronHigh -
GitPython 3.1.59: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracleGHSA-whh4-5q6c-9v3x published
Aug 26, 2026 by ByronModerate -
Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsingGHSA-g5vv-9gxw-82hx published
Aug 26, 2026 by ByronHigh -
Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)GHSA-7833-fr7j-v32q published
Aug 10, 2026 by ByronHigh -
Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCEGHSA-284h-m62q-gf8w published
Aug 10, 2026 by ByronHigh -
clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destinationGHSA-8mcc-hrx5-hvxc published
Aug 10, 2026 by ByronHigh -
Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()GHSA-5xxx-qhh7-9287 published
Aug 10, 2026 by ByronModerate -
TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)GHSA-3wxw-xv34-2frg published
Aug 10, 2026 by ByronModerate -
Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()GHSA-hh9p-6wh2-4mfc published
Aug 4, 2026 by ByronModerate -
Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooksGHSA-9rj7-rf2p-w77r published
Aug 4, 2026 by ByronHigh