CVE-2026-78678

Name
CVE-2026-78678
Description
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287
disclosure@vulncheck.com https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* py3-gitpython >= None < 3.1.59

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-gitpython edge-community 3.1.61-r0 Wen Heping <wenhepingalpine@sohu.com> fixed
py3-gitpython edge-community 3.1.57-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.49-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.46-r1 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.46-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.44-r0 None possibly vulnerable
py3-gitpython edge-community 3.1.43-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-gitpython edge-community 3.1.37-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-gitpython edge-community 3.1.35-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-gitpython 3.24-community 3.1.49-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable