
🚨High - GitPython RCE via check_unsafe_options Bypass (CVE-2026-73625) GitPython’s check_unsafe_options guard can be bypassed via single-character kwarg value smuggling in option dicts passed to Repo.clone_from/fetch/pull/push/ls_remote/iter_commits/blame/archive. Crafted options inject OS commands through the --upload-pack parameter, leading to remote code execution. 👉Affected: GitPython < 3.1.54 | Upgrade to 3.1.54
Post summary
CVE-2026-73625 enables remote code execution in GitPython via single‑character kwarg smuggling; upgrading to version 3.1.54 mitigates the vulnerability.

