Vulnerabilidades em gitpython-developers
34 resultadosAnálise Vexday
GitPython tem 7 vulnerabilidades catalogadas, com 4 divulgadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas de severidade máxima, reduzindo a urgência imediata. A fraqueza predominante é traversal de diretório (CWE-22), típica em operações com caminhos de arquivo, exigindo validação rigorosa de entrada em versões atuais.
CVE-2026-76222HIGHGitPython before 3.1.58 Path Traversal via .gitmodules Submodule NameEPSS 0.4%CVE-2026-78678HIGHGitPython before 3.1.59 Arbitrary File Read via Repo.blame()EPSS 0.4%CVE-2026-87818HIGHGitPython 3.1.59 Local File Content Oracle via --no-indexEPSS 0.4%CVE-2026-73619HIGHGitPython before 3.1.57 Arbitrary File Read via Repo.archive()EPSS 0.4%CVE-2026-76217HIGHGitPython before 3.1.58 Arbitrary File Read via pathspec-from-fileEPSS 0.4%CVE-2026-87817HIGHGitPython before 3.1.60 Remote Code Execution via Git Directory ImpersonationEPSS 0.4%CVE-2026-73621MEDIUMGitPython before 3.1.56 Arbitrary File Truncation via Commit.countEPSS 0.4%CVE-2026-67322HIGHGitPython before 3.1.52 Environment Variable Exfiltration via clone_fromEPSS 0.3%CVE-2024-22190HIGHUntrusted search path under some conditions on Windows allows arbitrary code executionEPSS 0.3%CVE-2026-69097HIGHGitPython before 3.1.53 Config Injection via Submodule NamesEPSS 0.3%CVE-2026-78679HIGHGitPython before 3.1.59 Arbitrary File Read via TagReference.createEPSS 0.3%CVE-2026-67326HIGHGitPython before 3.1.50 Newline Injection via config_writer sectionEPSS 0.3%CVE-2026-44244HIGHGitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathEPSS 0.2%CVE-2026-78675HIGHGitPython before 3.1.59 Local File Content Disclosure via .gitmodulesEPSS 0.2%