pkg:PyPI/gitpython
14 total CVEsCRITICAL2HIGH10MEDIUM2
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.8CVE-2023-40267GitPython vulnerable to remote code execution due to insufficient sanitization of input argumentsfrom 0, < 3.1.32
- CRITICAL9.8CVE-2023-40267GitPython vulnerable to remote code execution due to insufficient sanitization of input argumentsfrom 0, < ca965ecc81853bca7675261729143f54e5bf4cdd | from 0, < 3.1.32
- >= 3.1.30, < 3.1.47
- HIGH8.1CVE-2026-42284GitPython: Unsafe option check validates multi_options before shlex.split transformationfrom 0, < 3.1.47
- from 0, < 3.1.30
- from 0, < 3.1.30
- HIGH7.8CVE-2026-44244GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathfrom 0, < 3.1.49
- HIGH7.8CVE-2024-22190Untrusted search path under some conditions on Windows allows arbitrary code executionfrom 0, < 3.1.41
- HIGH7.8CVE-2024-22190Untrusted search path under some conditions on Windows allows arbitrary code executionfrom 0, < ef3192cc414f2fd9978908454f6fd95243784c7f | from 0, < 3.1.41
- HIGH7.8CVE-2023-40590GitPython untrusted search path on Windows systems leading to arbitrary code executionfrom 0, < 3.1.33
- HIGH7.8CVE-2023-40590GitPython untrusted search path on Windows systems leading to arbitrary code executionfrom 0, < 3.1.33
- HIGH7.1CVE-2026-44243GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repositoryfrom 0, < 3.1.48
- from 0, < 3.1.37
- from 0, < 3.1.35