CVE-2026-44243

EUVD-2026-28413
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.52%
Affected Products (NVD)
VendorProductVersion
gitpython_projectgitpython
𝑥
< 3.1.48
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-git
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
3.1.50-1
fixed
sid
3.1.50-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-git
bionic
Fixed 2.1.8-1ubuntu0.1~esm4
released
focal
Fixed 3.0.7-1ubuntu0.1~esm4
released
jammy
Fixed 3.1.24-1ubuntu0.1~esm3
released
noble
Fixed 3.1.37-3ubuntu0.1~esm2
released
questing
ignored
resolute
Fixed 3.1.46-1ubuntu0.1~esm1
released
trusty
Fixed 0.3.2~RC1-3ubuntu0.1~esm3
released
xenial
ignored