← Voltar à pesquisa de CVEs

CVE-2026-73621

GitPython

Descrição

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to -git rev-list- without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing -git rev-list --output=<path>- to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process-s privilege level (no content control, 0-byte truncation).

CVSS 5.4EPSS 0.199%Risco 0.55
Ver fonte
Publicação
2026-08-13 12:17:27
Versões afetadas
<3.1.56
Tipo
Biblioteca
Última alteração
2026-08-14 19:18:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L