GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitpython-developers
Gitpython-developers gitpython |
|
| Vendors & Products |
Gitpython-developers
Gitpython-developers gitpython |
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message. | |
| Title | GitPython before 3.1.59 Arbitrary File Read via TagReference.create | |
| First Time appeared |
Gitpython Project
Gitpython Project gitpython |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitpython Project
Gitpython Project gitpython |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:36.339Z
Reserved: 2026-08-25T01:17:12.262Z
Link: CVE-2026-78679
No data.
Status : Received
Published: 2026-08-25T02:16:52.470
Modified: 2026-08-25T02:16:52.470
Link: CVE-2026-78679
No data.
OpenCVE Enrichment
Updated: 2026-08-25T05:30:16Z
Weaknesses