Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44243

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.

A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows attackers to supply a specially crafted reference path to an application utilizing GitPython. Due to insufficient validation of these paths during reference creation, renaming, or deletion, an attacker can write, overwrite, move, or delete files outside the intended Git repository directory. This could lead to unauthorized modification or deletion of critical system files.

Отчет

This flaw in GitPython is rated as Moderate as it allows an attacker to perform arbitrary file write, overwrite, move, or delete operations outside of a Git repository. This is possible by supplying a crafted reference path to an application that uses GitPython, leading to potential unauthorized modification or deletion of critical system files. The impact is significant due to the potential for data integrity compromise on systems utilizing affected GitPython versions. However, exploitation is unlikely as it requires an application to use GitPython affected functions with user-supplied data. The vulnerability is not automatically exploitable simply because GitPython is installed or used. It requires to pass user-controlled data into the affected functions - thus AC:H.

Меры по смягчению последствий

Applications using GitPython should validate and sanitize all reference path inputs before passing them to GitPython's reference creation, rename, and delete APIs. Specifically, reject any reference path containing path traversal sequences such as "..". In Red Hat products, exploitation requires the ability to supply a crafted Git reference name to an application using GitPython — environments that do not expose GitPython reference operations to untrusted user input are not susceptible to this attack. Updating to GitPython 3.1.48 or later fully resolves this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/hub-rhel9Fix deferred
Red Hat Ansible Automation Platform 2automation-controllerFix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2467796GitPython: GitPython: Arbitrary file write via crafted reference paths

EPSS

Процентиль: 34%
0.00419
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
3 месяца назад

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.

CVSS3: 7.1
nvd
3 месяца назад

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.

CVSS3: 7.1
debian
3 месяца назад

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 9.1
redos
20 дней назад

Уязвимость GitPython

CVSS3: 7.1
github
3 месяца назад

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

EPSS

Процентиль: 34%
0.00419
Низкий

6.3 Medium

CVSS3