Vulnerabilidades em gitpython-developers
13 resultadosAnálise Vexday
GitPython tem 7 vulnerabilidades catalogadas, com 4 divulgadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas de severidade máxima, reduzindo a urgência imediata. A fraqueza predominante é traversal de diretório (CWE-22), típica em operações com caminhos de arquivo, exigindo validação rigorosa de entrada em versões atuais.
CVE-2026-67325HIGHGitPython before 3.1.51 Command Injection via option prefix abbreviationEPSS 1.5%CVE-2023-41040MEDIUMGitPython blind local file inclusionEPSS 1.0%CVE-2026-67323HIGHGitPython before 3.1.51 Command Injection via unguarded Git optionsEPSS 1.0%CVE-2026-42215HIGHGitPython: Command injection via Git options bypassEPSS 0.7%CVE-2026-42284HIGHGitPython: Unsafe option check validates multi_options before shlex.split transforms itEPSS 0.6%CVE-2023-40590HIGHUntrusted search path on Windows systems leading to arbitrary code executionEPSS 0.5%CVE-2026-44243HIGHGitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repositoryEPSS 0.4%CVE-2026-67324CRITICALGitPython 3.1.50 Authentication Bypass via Joined Short OptionsEPSS 0.4%CVE-2024-22190HIGHUntrusted search path under some conditions on Windows allows arbitrary code executionEPSS 0.3%CVE-2026-67322HIGHGitPython before 3.1.52 Environment Variable Exfiltration via clone_fromEPSS 0.3%CVE-2026-44244HIGHGitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathEPSS 0.2%CVE-2026-67326HIGHGitPython before 3.1.50 Newline Injection via config_writer sectionEPSS 0.2%CVE-2026-69097HIGHGitPython before 3.1.53 Config Injection via Submodule NamesEPSS 0.2%