CVE-2026-42215Disclosure(gitpython_project / gitpython)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitpython

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
gitpython

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-09-09: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 105-0705-0805-0909-09
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-072
Disclosure1General1
2026-05-081
Disclosure1
2026-05-091
Disclosure1
2026-09-091
General1
Full discourse5 posts
  • DailyCVE@dailycve
    General

    🟠 GitPython, Arbitrary File Read via Unsafe Option Forwarding, #CVE-2026-42215 (Medium) -DC-Sep2026-2248 https://dailycve.com/gitpython-arbitrary-file-read-via-unsafe-option-forwarding-cve-2026-42215-medium-dc-sep2026-2248/

    Post summary

    The post merely announces the CVE with minimal details and lacks any actionable technical or mitigation information.

    0000040
    237 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 GitPython, Configuration Injection, #CVE-2026-42215 Bypass (High) https://dailycve.com/gitpython-configuration-injection-cve-2026-42215-bypass-high/

    Post summary

    A new GitPython configuration injection vulnerability, CVE-2026-42215, has been disclosed as a high severity issue.

    0000039
    198 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42215 Remote Code Execution in GitPython 3.1.30 Through 3.1.46 ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42215 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE-2026-42215, noting a remote code execution flaw affecting specific GitPython versions, but provides no additional details such as a PoC, exploit code, patch, or evidence of active exploitation.

    0000058
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42215 GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --u… https://www.cve.org/CVERecord?id=CVE-2026-42215 ----- Traducción: CVE-2026-42215 Git… http://infoflow.cloud`

    Post summary

    The tweet merely announces CVE‑2026‑42215 for GitPython, noting it blocks certain dangerous Git options, with no evidence of exploits, patches, or activity.

    0000030
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42215 GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --u… https://www.cve.org/CVERecord?id=CVE-2026-42215

    Post summary

    The text announces a CVE in GitPython that affects versions 3.1.30‑3.1.46 by blocking dangerous Git options, without mentioning exploits, patches, or in‑the‑wild activity.

    00000189
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitpython_projectgitpython-python-

Explore more