Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2026-06621

3 месяца назад

Уязвимость функций Repo.clone_from(), Remote.fetch(), Remote.pull() или Remote.push() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260713-73-0049

20 дней назад

Уязвимость GitPython

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-42215

3 месяца назад

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-42215

3 месяца назад

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-42215

3 месяца назад

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rpm5-65cw-6hj4

3 месяца назад

GitPython has Command Injection via Git options bypass

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20777-1

3 месяца назад

Security update for python-GitPython

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-06621

Уязвимость функций Repo.clone_from(), Remote.fetch(), Remote.pull() или Remote.push() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
1%
Низкий
3 месяца назад
redos логотип
ROS-20260713-73-0049

Уязвимость GitPython

CVSS3: 8.8
1%
Низкий
20 дней назад
ubuntu логотип
CVE-2026-42215

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.

CVSS3: 8.8
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42215

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.

CVSS3: 8.8
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-42215

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-rpm5-65cw-6hj4

GitPython has Command Injection via Git options bypass

CVSS3: 8.8
1%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20777-1

Security update for python-GitPython

3 месяца назад

Уязвимостей на страницу