{"apiVersion":"1.0","identifier":"CVE-2026-78678","description":"GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.","publishedAt":"2026-08-25T02:16:52","lastModifiedAt":"2026-08-25T16:17:27","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78678","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00227,"riskScore":0.66,"affectedProduct":"GitPython","affectedVersions":"<3.1.59","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-78678","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-78678","en":"https://www.redsauce.net/en/cves/CVE-2026-78678","fr":"https://www.redsauce.net/fr/cves/CVE-2026-78678","pt":"https://www.redsauce.net/pt/cves/CVE-2026-78678","de":"https://www.redsauce.net/de/cves/CVE-2026-78678","sk":"https://www.redsauce.net/sk/cves/CVE-2026-78678","el":"https://www.redsauce.net/el/cves/CVE-2026-78678"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-78678"}}