Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-78678

Опубликовано: 25 авг. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
24 дня назад

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

CVSS3: 6.5
nvd
24 дня назад

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

CVSS3: 6.5
debian
24 дня назад

GitPython versions before 3.1.59 contain an incomplete denylist in the ...

CVSS3: 6.5
github
9 дней назад

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость функций Repo.blame() и Repo.blame_incremental() механизма защиты unsafe_git_revision_options библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

6.5 Medium

CVSS3