Количество 6
Количество 6
CVE-2026-87817
(GitPython before 3.1.60 fails to properly validate the git directory l ...)
CVE-2026-87817
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
CVE-2026-87817
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
CVE-2026-87817
GitPython before 3.1.60 fails to properly validate the git directory l ...
GHSA-2pxq-5vcg-rq29
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
BDU:2026-14474
Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-87817 (GitPython before 3.1.60 fails to properly validate the git directory l ...) | CVSS3: 8.8 | 0% Низкий | 6 дней назад | |
CVE-2026-87817 GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository. | CVSS3: 8.8 | 0% Низкий | 7 дней назад | |
CVE-2026-87817 GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository. | CVSS3: 8.8 | 0% Низкий | 7 дней назад | |
CVE-2026-87817 GitPython before 3.1.60 fails to properly validate the git directory l ... | CVSS3: 8.8 | 0% Низкий | 7 дней назад | |
GHSA-2pxq-5vcg-rq29 GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository. | CVSS3: 8.8 | 0% Низкий | 7 дней назад | |
BDU:2026-14474 Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 21 день назад |
Уязвимостей на страницу