Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitpython-developers
Gitpython-developers gitpython |
|
| Vendors & Products |
Gitpython-developers
Gitpython-developers gitpython |
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band. | |
| Title | GitPython before 3.1.57 Arbitrary File Overwrite and Read | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T15:01:15.162Z
Reserved: 2026-08-13T11:16:27.835Z
Link: CVE-2026-73620
Updated: 2026-08-13T15:01:11.108Z
Status : Received
Published: 2026-08-13T12:17:27.057
Modified: 2026-08-13T15:20:20.690
Link: CVE-2026-73620
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:15:04Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')