GHSA-4vpg-pfj8-m33q
Dashboard / Vulnerabilities / GHSA-4vpg-pfj8-m33q
GHSA-4vpg-pfj8-m33q
Summary: Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-956x-8gvw-wg5v. This link is maintained to preserve external references. ## Original Description GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.
References: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5v, https://nvd.nist.gov/vuln/detail/CVE-2026-67323, https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-options
Affected packages
Package
Name: gitpython
Purl: pkg:pypi/gitpython
Affected ranges
Type: ECOSYSTEM
Events:
