gitpython-developers GitPython

4 known vulnerabilities in gitpython-developers GitPython, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100689 CVSS 8.7 high GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior…
  • CVE-2026-87819 CVSS 8.7 high GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit…
  • CVE-2026-87818 CVSS 7.1 high GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths…
  • CVE-2026-87817 CVSS 8.7 high GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using…