Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-78678

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
Версия до 3.1.59 (исключая)

EPSS

Процентиль: 15%
0.0024
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 6.5
ubuntu
24 дня назад

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

CVSS3: 6.5
redhat
24 дня назад

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

CVSS3: 6.5
debian
24 дня назад

GitPython versions before 3.1.59 contain an incomplete denylist in the ...

CVSS3: 6.5
github
9 дней назад

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость функций Repo.blame() и Repo.blame_incremental() механизма защиты unsafe_git_revision_options библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 15%
0.0024
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-88