CVE-2026-87819GitPython before 3.1.60 Denial of Service via ReDoS Exploitation status Not confirmed Fix YesAffected product G GitPython Published 09/09/2026 Severity High CVE-2026-87818GitPython 3.1.59 Local File Content Oracle via --no-index Exploitation status Public exploit Fix YesAffected product G GitPython Published 09/09/2026 Severity High CVE-2026-87817GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation Exploitation status Not known exploited Fix YesAffected product G GitPython Published 09/09/2026 Severity High CVE-2026-78679GitPython before 3.1.59 Arbitrary File Read via TagReference.create Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/25/2026 Severity High CVE-2026-78678GitPython before 3.1.59 Arbitrary File Read via Repo.blame() Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/25/2026 Severity High CVE-2026-78677GitPython before 3.1.59 Path Traversal via separate-git-dir Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/25/2026 Severity High CVE-2026-78676GitPython before 3.1.59 Remote Code Execution via Config Injection Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/25/2026 Severity Critical CVE-2026-78675GitPython before 3.1.59 Local File Content Disclosure via .gitmodules Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/25/2026 Severity High CVE-2026-76222GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/19/2026 Severity High CVE-2026-76221GitPython before 3.1.58 Config Injection via option-name Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/19/2026 Severity High CVE-2026-76220GitPython before 3.1.58 Command Execution via split_single_char_options Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/19/2026 Severity High CVE-2026-76219GitPython before 3.1.58 Arbitrary File Overwrite via read-tree Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/19/2026 Severity High CVE-2026-76218GitPython before 3.1.58 Remote Code Execution via Repo.init Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/19/2026 Severity High CVE-2026-76217GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/19/2026 Severity High CVE-2026-73625GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/13/2026 Severity High CVE-2026-73624GitPython before 3.1.54 Arbitrary File Overwrite via diff Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/13/2026 Severity High CVE-2026-73623GitPython before 3.1.54 Remote Code Execution via --template Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/13/2026 Severity High CVE-2026-73622GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/13/2026 Severity High CVE-2026-73621GitPython before 3.1.56 Arbitrary File Truncation via Commit.count Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/13/2026 Severity Medium CVE-2026-73620GitPython before 3.1.57 Arbitrary File Overwrite and Read Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/13/2026 Severity High CVE-2026-73619GitPython before 3.1.57 Arbitrary File Read via Repo.archive() Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/13/2026 Severity High CVE-2026-69097GitPython before 3.1.53 Config Injection via Submodule Names Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/03/2026 Severity High CVE-2026-67326GitPython before 3.1.50 Newline Injection via config_writer section Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/01/2026 Severity High CVE-2026-67324GitPython 3.1.50 Authentication Bypass via Joined Short Options Exploitation status Not known exploited Fix YesAffected product G GitPython Published 08/01/2026 Severity Critical CVE-2026-67323GitPython before 3.1.51 Command Injection via unguarded Git options Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/01/2026 Severity High CVE-2026-67322GitPython before 3.1.52 Environment Variable Exfiltration via clone_from Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/01/2026 Severity High CVE-2026-67325GitPython before 3.1.51 Command Injection via option prefix abbreviation Exploitation status Public exploit Fix YesAffected product G GitPython Published 08/01/2026 Severity High CVE-2026-44243GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository Exploitation status Public exploit Fix YesAffected product G GitPython Published 05/07/2026 Severity High CVE-2026-44244GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath Exploitation status Public exploit Fix YesAffected product G GitPython Published 05/07/2026 Severity High CVE-2026-42284GitPython: Unsafe option check validates multi_options before shlex.split transforms it Exploitation status Public exploit Fix YesAffected product G GitPython Published 05/07/2026 Severity High CVE-2026-42215GitPython: Command injection via Git options bypass Exploitation status Public exploit Fix YesAffected product G GitPython Published 05/07/2026 Severity High CVE-2024-22190Untrusted search path under some conditions on Windows allows arbitrary code execution Exploitation status Public exploit Fix YesAffected product G GitPython Published 01/11/2024 Severity High CVE-2023-41040GitPython blind local file inclusion Exploitation status Public exploit Fix Not confirmed Affected product G GitPython Published 08/30/2023 Severity Medium CVE-2023-40590Untrusted search path on Windows systems leading to arbitrary code execution Exploitation status Public exploit Fix Not confirmed Affected product G GitPython Published 08/28/2023 Severity High