Количество 9
Количество 9
GHSA-5xxx-qhh7-9287
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
CVE-2026-78678
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.
CVE-2026-78678
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.
CVE-2026-78678
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.
CVE-2026-78678
GitPython versions before 3.1.59 contain an incomplete denylist in the ...
BDU:2026-12784
Уязвимость функций Repo.blame() и Repo.blame_incremental() механизма защиты unsafe_git_revision_options библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260908-80-0105
Уязвимость GitPython
ROS-20260908-73-0092
Уязвимость GitPython
SUSE-SU-2026:4072-1
Security update for python-GitPython
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5xxx-qhh7-9287 GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame() | CVSS3: 6.5 | 0% Низкий | 9 дней назад | |
CVE-2026-78678 GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller. | CVSS3: 6.5 | 0% Низкий | 24 дня назад | |
CVE-2026-78678 GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller. | CVSS3: 6.5 | 0% Низкий | 24 дня назад | |
CVE-2026-78678 GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller. | CVSS3: 6.5 | 0% Низкий | 24 дня назад | |
CVE-2026-78678 GitPython versions before 3.1.59 contain an incomplete denylist in the ... | CVSS3: 6.5 | 0% Низкий | 24 дня назад | |
BDU:2026-12784 Уязвимость функций Repo.blame() и Repo.blame_incremental() механизма защиты unsafe_git_revision_options библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260908-80-0105 Уязвимость GitPython | CVSS3: 6.5 | 0% Низкий | 10 дней назад | |
ROS-20260908-73-0092 Уязвимость GitPython | CVSS3: 6.5 | 0% Низкий | 10 дней назад | |
SUSE-SU-2026:4072-1 Security update for python-GitPython | 9 дней назад |
Уязвимостей на страницу