Количество 7
Количество 7
GHSA-rpm5-65cw-6hj4
GitPython has Command Injection via Git options bypass
CVE-2026-42215
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.
CVE-2026-42215
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.
CVE-2026-42215
GitPython is a python library used to interact with Git repositories. ...
BDU:2026-06621
Уязвимость функций Repo.clone_from(), Remote.fetch(), Remote.pull() или Remote.push() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды
ROS-20260713-73-0049
Уязвимость GitPython
openSUSE-SU-2026:20777-1
Security update for python-GitPython
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-rpm5-65cw-6hj4 GitPython has Command Injection via Git options bypass | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-42215 GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-42215 GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-42215 GitPython is a python library used to interact with Git repositories. ... | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
BDU:2026-06621 Уязвимость функций Repo.clone_from(), Remote.fetch(), Remote.pull() или Remote.push() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
ROS-20260713-73-0049 Уязвимость GitPython | CVSS3: 8.8 | 1% Низкий | 20 дней назад | |
openSUSE-SU-2026:20777-1 Security update for python-GitPython | 3 месяца назад |
Уязвимостей на страницу