Vulnerabilidades en gitpython-developers

34 resultados
Análisis Vexday

GitPython tem 7 vulnerabilidades catalogadas, com 4 divulgadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas de severidade máxima, reduzindo a urgência imediata. A fraqueza predominante é traversal de diretório (CWE-22), típica em operações com caminhos de arquivo, exigindo validação rigorosa de entrada em versões atuais.

CVE-2026-67325HIGHGitPython before 3.1.51 Command Injection via option prefix abbreviationEPSS 2.2%CVE-2026-67323HIGHGitPython before 3.1.51 Command Injection via unguarded Git optionsEPSS 1.3%CVE-2023-41040MEDIUMGitPython blind local file inclusionEPSS 1.1%CVE-2026-73625HIGHGitPython before 3.1.54 Remote Code Execution via kwarg value smugglingEPSS 0.9%CVE-2026-76220HIGHGitPython before 3.1.58 Command Execution via split_single_char_optionsEPSS 0.9%CVE-2026-42215HIGHGitPython: Command injection via Git options bypassEPSS 0.9%CVE-2026-73623HIGHGitPython before 3.1.54 Remote Code Execution via --templateEPSS 0.8%CVE-2026-76218HIGHGitPython before 3.1.58 Remote Code Execution via Repo.initEPSS 0.8%CVE-2026-78676CRITICALGitPython before 3.1.59 Remote Code Execution via Config InjectionEPSS 0.8%CVE-2026-76221HIGHGitPython before 3.1.58 Config Injection via option-nameEPSS 0.8%CVE-2026-42284HIGHGitPython: Unsafe option check validates multi_options before shlex.split transforms itEPSS 0.7%CVE-2026-78677HIGHGitPython before 3.1.59 Path Traversal via separate-git-dirEPSS 0.7%CVE-2026-67324CRITICALGitPython 3.1.50 Authentication Bypass via Joined Short OptionsEPSS 0.6%CVE-2026-73620HIGHGitPython before 3.1.57 Arbitrary File Overwrite and ReadEPSS 0.6%CVE-2026-76219HIGHGitPython before 3.1.58 Arbitrary File Overwrite via read-treeEPSS 0.5%CVE-2026-87819HIGHGitPython before 3.1.60 Denial of Service via ReDoSEPSS 0.5%CVE-2026-73622HIGHGitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()EPSS 0.5%CVE-2023-40590HIGHUntrusted search path on Windows systems leading to arbitrary code executionEPSS 0.5%CVE-2026-73624HIGHGitPython before 3.1.54 Arbitrary File Overwrite via diffEPSS 0.5%CVE-2026-44243HIGHGitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repositoryEPSS 0.4%