Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cm2-456v-hrq7

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.2
CVSS3: 8.1

Описание

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

EPSS

Процентиль: 20%
0.00277
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 8.1
ubuntu
16 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

CVSS3: 8.1
redhat
16 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

CVSS3: 8.1
nvd
16 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

CVSS3: 8.1
debian
16 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite v ...

CVSS3: 8.1
fstec
около 1 месяца назад

Уязвимость метода Diffable.diff библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписывать произвольные файлы в системе

EPSS

Процентиль: 20%
0.00277
Низкий

7.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-88