Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11883

Опубликовано: 22 июл. 2026
Источник: fstec
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

Уязвимость механизма check_unsafe_options библиотеки Python для взаимодействия с git-репозиториями GitPython связана с непринятием мер по нейтрализации специальных элементов. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, перезаписывать произвольные файлы в системе

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения

Наименование ПО

Red Hat Satellite
Red Hat OpenStack Platform
OpenShift AI
Red Hat AI Inference Server
Red Hat Enterprise Linux AI
Ansible Automation Platform
Pen Drive Powered by Red Hat Lightspeed
Migration Toolkit for Applications
Exploit Intelligence
GitPython

Версия ПО

6 (Red Hat Satellite)
16.2 (Red Hat OpenStack Platform)
17.1 (Red Hat OpenStack Platform)
- (OpenShift AI)
- (Red Hat AI Inference Server)
3 (Red Hat Enterprise Linux AI)
2 (Ansible Automation Platform)
- (Pen Drive Powered by Red Hat Lightspeed)
8 (Migration Toolkit for Applications)
- (Exploit Intelligence)
до 3.1.54 (GitPython)

Тип ПО

Прикладное ПО информационных систем
ПО программно-аппаратного средства
ПО для разработки ИИ
Операционная система

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux AI 3

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 9)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-r9mr-m37c-5fr3
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-73625

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 41%
0.00502
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
16 дней назад

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

CVSS3: 8.8
redhat
16 дней назад

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

CVSS3: 8.8
nvd
16 дней назад

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

CVSS3: 8.8
debian
16 дней назад

GitPython versions before 3.1.54 contain a remote code execution vulne ...

CVSS3: 8.8
github
16 дней назад

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

EPSS

Процентиль: 41%
0.00502
Низкий

8.8 High

CVSS3

9 Critical

CVSS2