3.1.50
16 years ago
2 months ago
Known vulnerabilities in the gitpython package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Command Injection via the Note: This vulnerability bypasses the patch for CVE-2026-42215. How to fix Command Injection? Upgrade | [,3.1.50) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | [,3.1.49) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Directory Traversal through insufficient validation of reference paths in the creation, renaming, and deletion. An attacker can write, overwrite, move, or delete files outside the intended directory by supplying crafted reference paths to the relevant APIs. How to fix Directory Traversal? Upgrade | [,3.1.48) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Command Injection via the How to fix Command Injection? Upgrade | [3.1.30,3.1.47) |
GitPython is a python library used to interact with Git repositories Affected versions of this package are vulnerable to Arbitrary Argument Injection in the How to fix Arbitrary Argument Injection? Upgrade | [,3.1.47) |