CVE-2026-73624: high-severity vulnerability in gitpython-developers GitPython
GitPython before 3.1.54 Arbitrary File Overwrite via diff
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 0.6%
exploitation probability
0.6%top 56% of all CVEs
observed exploitation
nono source reports it
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
gitpython-developers · GitPythonRelated CVEs — gitpython-developers GitPython
In the same product, most dangerous first.
CVE-2026-67325HIGHGitPython before 3.1.51 Command Injection via option prefix abbreviationEPSS 2.2%CVE-2026-67323HIGHGitPython before 3.1.51 Command Injection via unguarded Git optionsEPSS 1.3%CVE-2023-41040MEDIUMGitPython blind local file inclusionEPSS 1.1%CVE-2026-73625HIGHGitPython before 3.1.54 Remote Code Execution via kwarg value smugglingEPSS 0.9%CVE-2026-76220HIGHGitPython before 3.1.58 Command Execution via split_single_char_optionsEPSS 0.9%CVE-2026-42215HIGHGitPython: Command injection via Git options bypassEPSS 0.9%