Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3x4-5jfw-2mqc

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

EPSS

Процентиль: 13%
0.00228
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 6.5
ubuntu
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

CVSS3: 6.5
redhat
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

CVSS3: 6.5
nvd
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

CVSS3: 6.5
debian
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_ ...

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость функции Repo.archive() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 13%
0.00228
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-73