Количество 6
Количество 6
CVE-2026-42284
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.
CVE-2026-42284
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.
CVE-2026-42284
GitPython is a python library used to interact with Git repositories. ...
ROS-20260713-73-0047
Уязвимость GitPython
GHSA-x2qx-6953-8485
GitPython: Unsafe option check validates multi_options before shlex.split transformation
openSUSE-SU-2026:20777-1
Security update for python-GitPython
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-42284 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-42284 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47. | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
CVE-2026-42284 GitPython is a python library used to interact with Git repositories. ... | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
ROS-20260713-73-0047 Уязвимость GitPython | CVSS3: 9.8 | 1% Низкий | 20 дней назад | |
GHSA-x2qx-6953-8485 GitPython: Unsafe option check validates multi_options before shlex.split transformation | CVSS3: 8.1 | 1% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20777-1 Security update for python-GitPython | 3 месяца назад |
Уязвимостей на страницу