Dependency scanning
Check whether gitpython is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-67325
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
CVE-2026-78675
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
CVE-2026-78679
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
CVE-2026-87818
CVE-2026-87818
CVE-2026-67326
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
CVE-2026-69097
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
CVE-2026-69097
CVE-2026-69097
CVE-2026-67326
CVE-2026-67326
CVE-2026-87817
CVE-2026-87817
CVE-2026-87819
CVE-2026-87819
CVE-2026-67324
CVE-2026-67324
CVE-2026-73623
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
CVE-2026-73619
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
CVE-2026-73621
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
CVE-2026-67324
GitPython unsafe clone option gate bypass through joined short options
CVE-2026-73625
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
CVE-2026-73622
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
CVE-2026-73620
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
CVE-2026-73623
CVE-2026-73623
CVE-2026-73619
CVE-2026-73619
CVE-2026-73621
CVE-2026-73621
CVE-2026-73620
CVE-2026-73620
CVE-2026-73622
CVE-2026-73622
CVE-2026-73625
CVE-2026-73625
CVE-2026-76217
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
CVE-2026-76220
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
CVE-2026-76218
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
CVE-2026-67322
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
CVE-2026-76219
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
CVE-2026-67323
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
CVE-2026-76219
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
CVE-2026-67322
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
CVE-2026-67325
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
CVE-2026-76217
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
CVE-2026-76220
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
CVE-2026-67323
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
CVE-2026-76218
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
CVE-2026-78679
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
CVE-2026-76221
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
CVE-2026-42284
GitPython: Unsafe option check validates multi_options before shlex.split transformation
CVE-2026-42215
GitPython has Command Injection via Git options bypass
CVE-2026-73624
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
CVE-2026-44244
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
CVE-2026-44243
GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
CVE-2024-22190
Untrusted search path under some conditions on Windows allows arbitrary code execution
CVE-2023-40590
GitPython untrusted search path on Windows systems leading to arbitrary code execution
GHSA-wv46-xpj8-pw53
Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GHSA-298h-jpq4-m665
Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
GHSA-3vrx-526r-64rm
Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GHSA-w672-239g-c3gr
Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
CVE-2026-76222
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GHSA-7jx3-jqcp-hhgc
Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GHSA-6rj2-96f5-chj9
Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GHSA-89ff-m8wv-p99r
Duplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
CVE-2026-78677
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
CVE-2026-78678
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
GHSA-9557-234j-7rv9
Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
GHSA-7r39-6q8m-qw68
Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
CVE-2026-78676
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
GHSA-crmc-f4m7-33fj
Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
GHSA-6r2r-ww24-7h52
Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GHSA-m4f3-g4cq-hqrx
Duplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-cw2r-r7mw-j3hc
Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options
GHSA-4vpg-pfj8-m33q
Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
CVE-2026-76221
CVE-2026-76221
CVE-2026-78676
CVE-2026-78676
CVE-2026-76222
CVE-2026-76222
CVE-2026-78677
CVE-2026-78677
CVE-2026-78675
CVE-2026-78675
CVE-2026-78678
CVE-2026-78678
CVE-2026-44244
CVE-2026-44244
CVE-2026-42215
CVE-2026-42215
CVE-2026-44243
CVE-2026-44243
CVE-2026-42284
CVE-2026-42284
CVE-2022-24439
CVE-2022-24439
CVE-2023-40267
GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments
CVE-2022-24439
GitPython vulnerable to Remote Code Execution due to improper user input validation
CVE-2023-41040
GitPython blind local file inclusion
CVE-2024-22190
CVE-2024-22190
CVE-2023-41040
CVE-2023-41040
CVE-2023-40590
CVE-2023-40590
CVE-2023-40267
CVE-2023-40267
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes