Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73619

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

A flaw was found in GitPython. This vulnerability allows an attacker to read arbitrary files from the filesystem. By exploiting an incomplete denylist in the unsafe_git_archive_options guard, an attacker can supply specific options, such as --add-file or --add-virtual-file, to the Repo.archive() function. This leads to unauthorized information disclosure at the privileges of the process running GitPython.

Отчет

This is a Moderate impact flaw in GitPython that allows an attacker to read arbitrary files from the filesystem. The vulnerability arises from an incomplete denylist in the unsafe_git_archive_options guard, which can be bypassed by supplying specific options to the Repo.archive() function. This could lead to unauthorized information disclosure in Red Hat products utilizing affected versions of GitPython, such as Red Hat OpenStack Platform and Red Hat Satellite.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Out of support scope
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Out of support scope
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2515265gitpython: GitPython: Arbitrary file read vulnerability via `Repo.archive()`

EPSS

Процентиль: 13%
0.00228
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

CVSS3: 6.5
nvd
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

CVSS3: 6.5
debian
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_ ...

CVSS3: 6.5
github
15 дней назад

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость функции Repo.archive() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 13%
0.00228
Низкий

6.5 Medium

CVSS3