CVE-2026-44243General(gitpython_project / gitpython)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch gitpython_project gitpython systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitpython

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-07)
  • 3 total mentions across 2 days

Affected systems

Products
gitpython

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-06: 105-0605-07
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-061
Patch1
2026-05-072
General2
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 GitPython Path Traversal Vulnerability: CVE-2026-44243 A flaw in GitPython reference APIs could allow attackers to write, move, or delete files outside the .git directory via crafted reference paths. Fixed in GitPython 3.1.48+ .#GitPython #Python #OpenSource #CyberSecurity

    Post summary

    The post reports a path traversal flaw in GitPython that allows manipulating files outside the .git directory, and notes that it has been patched in version 3.1.48 and later.

    0001089
    149 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-44243 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted … https://www.cve.org/CVERecord?id=CVE-2026-44243 ----- Traducción: CVE-2026-44243 Git… http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-44243 affecting GitPython, noting a vulnerability involving crafted input prior to version 3.1.48, but provides no further technical, exploit, or remediation details.

    0000028
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44243 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted … https://www.cve.org/CVERecord?id=CVE-2026-44243

    Post summary

    The post reports the existence of CVE‑2026‑44243 for GitPython but provides no actionable or detailed information beyond the reference link.

    00000163
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitpython_projectgitpython-python-

Explore more