82 Total advisories
82 Vulnerabilities
0 Malware

Dependency scanning

Check whether gitpython is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.8
PyPI

CVE-2026-67325

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

HIGH 8.4
PyPI

CVE-2026-78675

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

MEDIUM 6.5
PyPI

CVE-2026-78679

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

UNKNOWN
PyPI

CVE-2026-87818

CVE-2026-87818

HIGH 7.0
PyPI

CVE-2026-67326

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

HIGH 7.0
PyPI

CVE-2026-69097

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

HIGH 7.3
PyPI

CVE-2026-69097

CVE-2026-69097

HIGH 7.8
PyPI

CVE-2026-67326

CVE-2026-67326

UNKNOWN
PyPI

CVE-2026-87817

CVE-2026-87817

HIGH 7.5
PyPI

CVE-2026-87819

CVE-2026-87819

UNKNOWN
PyPI

CVE-2026-67324

CVE-2026-67324

HIGH 7.5
PyPI

CVE-2026-73623

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

MEDIUM 6.5
PyPI

CVE-2026-73619

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

MEDIUM 5.4
PyPI

CVE-2026-73621

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

UNKNOWN
PyPI

CVE-2026-67324

GitPython unsafe clone option gate bypass through joined short options

HIGH 8.8
PyPI

CVE-2026-73625

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

HIGH 7.5
PyPI

CVE-2026-73622

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

HIGH 8.1
PyPI

CVE-2026-73620

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

HIGH 8.8
PyPI

CVE-2026-73623

CVE-2026-73623

UNKNOWN
PyPI

CVE-2026-73619

CVE-2026-73619

UNKNOWN
PyPI

CVE-2026-73621

CVE-2026-73621

UNKNOWN
PyPI

CVE-2026-73620

CVE-2026-73620

UNKNOWN
PyPI

CVE-2026-73622

CVE-2026-73622

UNKNOWN
PyPI

CVE-2026-73625

CVE-2026-73625

MEDIUM 6.5
PyPI

CVE-2026-76217

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

HIGH 8.8
PyPI

CVE-2026-76220

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

HIGH 7.5
PyPI

CVE-2026-76218

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

HIGH 7.5
PyPI

CVE-2026-67322

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

HIGH 8.1
PyPI

CVE-2026-76219

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

HIGH 8.4
PyPI

CVE-2026-67323

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

HIGH 8.1
PyPI

CVE-2026-76219

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

HIGH 7.5
PyPI

CVE-2026-67322

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

HIGH 8.8
PyPI

CVE-2026-67325

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

MEDIUM 6.5
PyPI

CVE-2026-76217

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

HIGH 8.8
PyPI

CVE-2026-76220

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

HIGH 8.4
PyPI

CVE-2026-67323

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

HIGH 7.5
PyPI

CVE-2026-76218

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

MEDIUM 6.5
PyPI

CVE-2026-78679

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

HIGH 8.8
PyPI

CVE-2026-76221

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

HIGH 8.1
PyPI

CVE-2026-42284

GitPython: Unsafe option check validates multi_options before shlex.split transformation

HIGH 8.8
PyPI

CVE-2026-42215

GitPython has Command Injection via Git options bypass

HIGH 8.1
PyPI

CVE-2026-73624

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

HIGH 7.8
PyPI

CVE-2026-44244

GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

HIGH 7.1
PyPI

CVE-2026-44243

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

HIGH 7.8
PyPI

CVE-2024-22190

Untrusted search path under some conditions on Windows allows arbitrary code execution

HIGH 7.8
PyPI

CVE-2023-40590

GitPython untrusted search path on Windows systems leading to arbitrary code execution

HIGH 8.8
PyPI

GHSA-wv46-xpj8-pw53

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

HIGH 7.5
PyPI

GHSA-298h-jpq4-m665

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

HIGH 8.2
PyPI

GHSA-3vrx-526r-64rm

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

MEDIUM 6.5
PyPI

GHSA-w672-239g-c3gr

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

HIGH 8.2
PyPI

CVE-2026-76222

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

HIGH 8.1
PyPI

GHSA-7jx3-jqcp-hhgc

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

MEDIUM 6.5
PyPI

GHSA-6rj2-96f5-chj9

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

MEDIUM 6.5
PyPI

GHSA-89ff-m8wv-p99r

Duplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

HIGH 7.5
PyPI

CVE-2026-78677

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

MEDIUM 6.5
PyPI

CVE-2026-78678

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

CRITICAL 9.8
PyPI

GHSA-9557-234j-7rv9

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

HIGH 7.5
PyPI

GHSA-7r39-6q8m-qw68

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

CRITICAL 9.8
PyPI

CVE-2026-78676

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

HIGH 8.4
PyPI

GHSA-crmc-f4m7-33fj

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

HIGH 8.8
PyPI

GHSA-6r2r-ww24-7h52

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

HIGH 7.5
PyPI

GHSA-m4f3-g4cq-hqrx

Duplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

CRITICAL 9.8
PyPI

GHSA-cw2r-r7mw-j3hc

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

HIGH 8.4
PyPI

GHSA-4vpg-pfj8-m33q

Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

UNKNOWN
PyPI

CVE-2026-76221

CVE-2026-76221

UNKNOWN
PyPI

CVE-2026-78676

CVE-2026-78676

UNKNOWN
PyPI

CVE-2026-76222

CVE-2026-76222

UNKNOWN
PyPI

CVE-2026-78677

CVE-2026-78677

HIGH 7.8
PyPI

CVE-2026-78675

CVE-2026-78675

UNKNOWN
PyPI

CVE-2026-78678

CVE-2026-78678

HIGH 7.8
PyPI

CVE-2026-44244

CVE-2026-44244

HIGH 8.8
PyPI

CVE-2026-42215

CVE-2026-42215

HIGH 7.1
PyPI

CVE-2026-44243

CVE-2026-44243

CRITICAL 9.8
PyPI

CVE-2026-42284

CVE-2026-42284

UNKNOWN
PyPI

CVE-2022-24439

CVE-2022-24439

CRITICAL 9.8
PyPI

CVE-2023-40267

GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments

HIGH 8.1
PyPI

CVE-2022-24439

GitPython vulnerable to Remote Code Execution due to improper user input validation

MEDIUM 4.0
PyPI

CVE-2023-41040

GitPython blind local file inclusion

HIGH 7.8
PyPI

CVE-2024-22190

CVE-2024-22190

MEDIUM 6.5
PyPI

CVE-2023-41040

CVE-2023-41040

HIGH 7.8
PyPI

CVE-2023-40590

CVE-2023-40590

UNKNOWN
PyPI

CVE-2023-40267

CVE-2023-40267

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes