Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2726-phmx-rc26

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

EPSS

Процентиль: 50%
0.00693
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.5
ubuntu
15 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

CVSS3: 7.5
redhat
15 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

CVSS3: 7.5
nvd
15 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

CVSS3: 7.5
debian
15 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_ ...

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 50%
0.00693
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-78