Количество 5
Количество 5
CVE-2026-76219
(GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)
CVE-2026-76219
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
CVE-2026-76219
GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...
GHSA-7jx3-jqcp-hhgc
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
BDU:2026-12059
Уязвимость методов IndexFile.from_tree, IndexFile.reset и IndexFile.merge_tree библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписать произвольные файлы
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...) | CVSS3: 8.1 | 0% Низкий | 8 дней назад | |
CVE-2026-76219 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. | CVSS3: 8.1 | 0% Низкий | 8 дней назад | |
CVE-2026-76219 GitPython versions before 3.1.58 contain an arbitrary file overwrite v ... | CVSS3: 8.1 | 0% Низкий | 8 дней назад | |
GHSA-7jx3-jqcp-hhgc GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. | CVSS3: 8.1 | 0% Низкий | 8 дней назад | |
BDU:2026-12059 Уязвимость методов IndexFile.from_tree, IndexFile.reset и IndexFile.merge_tree библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписать произвольные файлы | CVSS3: 8.1 | 0% Низкий | 24 дня назад |
Уязвимостей на страницу