CVE-2026-73619: high-severity vulnerability in gitpython-developers GitPython
GitPython before 3.1.57 Arbitrary File Read via Repo.archive()
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
gitpython-developers · GitPythonRelated CVEs — gitpython-developers GitPython
In the same product, most dangerous first.
CVE-2026-67325HIGHGitPython before 3.1.51 Command Injection via option prefix abbreviationEPSS 2.2%CVE-2026-67323HIGHGitPython before 3.1.51 Command Injection via unguarded Git optionsEPSS 1.3%CVE-2023-41040MEDIUMGitPython blind local file inclusionEPSS 1.1%CVE-2026-73625HIGHGitPython before 3.1.54 Remote Code Execution via kwarg value smugglingEPSS 0.9%CVE-2026-76220HIGHGitPython before 3.1.58 Command Execution via split_single_char_optionsEPSS 0.9%CVE-2026-42215HIGHGitPython: Command injection via Git options bypassEPSS 0.9%