Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w672-239g-c3gr

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.

GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.

EPSS

Процентиль: 20%
0.00281
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 6.5
ubuntu
8 дней назад

(GitPython versions before 3.1.58 fail to validate options passed to gi ...)

CVSS3: 6.5
nvd
8 дней назад

GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.

CVSS3: 6.5
debian
8 дней назад

GitPython versions before 3.1.58 fail to validate options passed to gi ...

EPSS

Процентиль: 20%
0.00281
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-73