CVE 7.8 HIGH

GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository_CVE-2026-44243

7.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repositoryโ€™s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.

Basic Information

ID CVE-2026-44243
Source GitHub_M
Published May 7, 2026 at 18:22
Modified May 7, 2026 at 19:12

Affected Product

Vendor gitpython-developers
Product GitPython
Version < 3.1.48
Affected Versions gitpython-developers GitPython < 3.1.48

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.