Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-42284

3 месяца назад

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-42284

3 месяца назад

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-42284

3 месяца назад

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20260713-73-0047

20 дней назад

Уязвимость GitPython

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x2qx-6953-8485

3 месяца назад

GitPython: Unsafe option check validates multi_options before shlex.split transformation

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20777-1

3 месяца назад

Security update for python-GitPython

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42284

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.

CVSS3: 8.1
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42284

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--config", "core.hooksPath=/x"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.

CVSS3: 8.1
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-42284

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 8.1
1%
Низкий
3 месяца назад
redos логотип
ROS-20260713-73-0047

Уязвимость GitPython

CVSS3: 9.8
1%
Низкий
20 дней назад
github логотип
GHSA-x2qx-6953-8485

GitPython: Unsafe option check validates multi_options before shlex.split transformation

CVSS3: 8.1
1%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20777-1

Security update for python-GitPython

3 месяца назад

Уязвимостей на страницу