Vulnerability PYSEC-2026-3995
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 13, 2026 at 12:17 PM UTC
No summary available
0.1.7 and 0.3.1-beta2 - 3.1.53
0.1.7 and 0.3.1-beta2 - 3.1.53
Details
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
19 days ago
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
0.1.7 and 0.3.1-beta2 - 3.1.58 PYSEC-2026-3837
0.1.7 and 0.3.1-beta2 - 3.1.58 PYSEC-2026-3837
High Risk
19 days ago
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3838
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3838
High Risk
19 days ago
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3840
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3840
Medium Risk
19 days ago
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3841
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3841
High Risk
19 days ago
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3843
0.1.7 and 0.3.1-beta2 - 3.1.57 PYSEC-2026-3843
Impacted packages
Timeline
Published
1 month ago
August 13, 2026 at 12:17 PM UTC
Fixed (3.1.54)
2 months ago
July 22, 2026 at 04:08 AM UTC
Last Modified
2 hours ago
September 29, 2026 at 09:00 AM UTC