Количество 9
Количество 9
CVE-2026-76219
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
CVE-2026-76219
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
CVE-2026-76219
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
CVE-2026-76219
GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...
GHSA-4gmw-gg2m-w46p
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
BDU:2026-12059
Уязвимость методов IndexFile.from_tree, IndexFile.reset и IndexFile.merge_tree библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписать произвольные файлы
ROS-20260901-80-0025
Уязвимость GitPython
ROS-20260901-73-0020
Уязвимость GitPython
SUSE-SU-2026:4072-1
Security update for python-GitPython
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-76219 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. | CVSS3: 8.1 | 0% Низкий | 29 дней назад | |
CVE-2026-76219 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. | CVSS3: 8.1 | 0% Низкий | 29 дней назад | |
CVE-2026-76219 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. | CVSS3: 8.1 | 0% Низкий | 29 дней назад | |
CVE-2026-76219 GitPython versions before 3.1.58 contain an arbitrary file overwrite v ... | CVSS3: 8.1 | 0% Низкий | 29 дней назад | |
GHSA-4gmw-gg2m-w46p GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
BDU:2026-12059 Уязвимость методов IndexFile.from_tree, IndexFile.reset и IndexFile.merge_tree библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписать произвольные файлы | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
ROS-20260901-80-0025 Уязвимость GitPython | CVSS3: 8.1 | 0% Низкий | 17 дней назад | |
ROS-20260901-73-0020 Уязвимость GitPython | CVSS3: 8.1 | 0% Низкий | 17 дней назад | |
SUSE-SU-2026:4072-1 Security update for python-GitPython | 10 дней назад |
Уязвимостей на страницу