Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73624

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

A flaw was found in GitPython. This vulnerability allows a remote attacker to overwrite arbitrary files on the system. By failing to properly validate git options passed to the Diffable.diff method, an attacker can supply a malicious output argument to write patch content to attacker-controlled file paths, leading to potential system compromise.

Отчет

This is an Important arbitrary file overwrite vulnerability in GitPython's Diffable.diff method. It allows an attacker to write arbitrary content to chosen file paths at the process's privilege level by manipulating git options, which could lead to system compromise or privilege escalation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2515243gitpython: GitPython: Arbitrary File Overwrite via improper git option validation

EPSS

Процентиль: 20%
0.00277
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
15 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

CVSS3: 8.1
nvd
15 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

CVSS3: 8.1
debian
15 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite v ...

CVSS3: 8.1
github
15 дней назад

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

CVSS3: 8.1
fstec
около 1 месяца назад

Уязвимость метода Diffable.diff библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписывать произвольные файлы в системе

EPSS

Процентиль: 20%
0.00277
Низкий

8.1 High

CVSS3