CRITICAL 9.8 PyPI

GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments

GHSA-pr76-5cm5-w9cj · CVE-2023-40267 · PYSEC-2023-137

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from, making it vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

Ready to move

Start Securing

Free, no credit card | First findings in minutes