CVE-2026-73625Disclosure(gitpython_project / gitpython)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch gitpython_project gitpython systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitpython

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
gitpython

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-13: 2Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 208-13
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - GitPython RCE via check_unsafe_options Bypass (CVE-2026-73625) GitPython’s check_unsafe_options guard can be bypassed via single-character kwarg value smuggling in option dicts passed to Repo.clone_from/fetch/pull/push/ls_remote/iter_commits/blame/archive. Crafted options inject OS commands through the --upload-pack parameter, leading to remote code execution. 👉Affected: GitPython < 3.1.54 | Upgrade to 3.1.54

    Post summary

    CVE-2026-73625 enables remote code execution in GitPython via single‑character kwarg smuggling; upgrading to version 3.1.54 mitigates the vulnerability.

    0000080
    288 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 GitPython Mass Disclosure — 7 CVEs, CVSS 8.8 PEAK CVE-2026-73625 (8.8): check_unsafe_options bypass RCE CVE-2026-73620 (8.1): Unsafe option forwarding (checkout) → https://threataft.com/articles/gitpython-mass-disclosure-7-cves #cybersecurity #infosec #GitPython #Python #CICD #SupplyChain` #ThreatIntel

    Post summary

    The tweet announces a mass disclosure of seven GitPython CVEs, highlighting one with a CVSS 8.8 score that allows RCE via a check_unsafe_options bypass, and links to an article for more detail.

    0000038
    36 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitpython_projectgitpython-python-

Explore more