Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-298h-jpq4-m665

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.

GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.

EPSS

Процентиль: 40%
0.00492
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

(GitPython before 3.1.58 contains a remote code execution vulnerability ...)

CVSS3: 7.5
nvd
8 дней назад

GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.

CVSS3: 7.5
debian
8 дней назад

GitPython before 3.1.58 contains a remote code execution vulnerability ...

EPSS

Процентиль: 40%
0.00492
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-88