CVE-2026-73620
EUVD-2026-5782413.08.2026, 12:17
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitpython_project | gitpython | 𝑥 < 3.1.57 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases