{"apiVersion":"1.0","identifier":"CVE-2026-73621","description":"GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to -git rev-list- without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing -git rev-list --output=<path>- to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process-s privilege level (no content control, 0-byte truncation).","publishedAt":"2026-08-13T12:17:27","lastModifiedAt":"2026-08-14T19:18:00","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73621","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","epssProbability":0.00199,"riskScore":0.55,"affectedProduct":"GitPython","affectedVersions":"<3.1.56","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73621","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73621","en":"https://www.redsauce.net/en/cves/CVE-2026-73621","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73621","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73621","de":"https://www.redsauce.net/de/cves/CVE-2026-73621","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73621","el":"https://www.redsauce.net/el/cves/CVE-2026-73621"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73621"}}