CVE-2026-78678Active Exploitation(gitpython_project / gitpython)

LOWCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for gitpython_project gitpython systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitpython

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
gitpython

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2Active Exploitation · 2026-08-25: 1Technical Details · 2026-08-25: 208-25
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 25 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 📦 Outdated IT service management platform — unauthenticated file deletion reaching code execution (Combodo iTop CVE-2026-39975, CVE-2026-30864, CVE-2026-40877) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Actively-exploited Oracle web tier — unauthenticated read of critical data straight off the internet-facing front door (Oracle CVE-2026-21962) 📦 Outdated web database console — unauthenticated code execution on the host running it, no login needed (Adminer CVE-2026-56705, CVE-2026-56703, CVE-2026-34968, CVE-2026-56702, CVE-2026-56706, CVE-2026-56704, CVE-2026-34967, CVE-2026-34964, CVE-2026-34959) 📦 Vulnerable Git library pinned in a served manifest — attacker-chosen code runs on the next git command (GitPython CVE-2026-78676, CVE-2026-78677, CVE-2026-78678) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The post highlights an actively exploited Oracle CVE (CVE‑2026‑21962) along with other newly reported vulnerabilities, but does not provide PoC or patch information.

    0100072
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78678 Arbitrary File Read in GitPython Before 3.1.59 via Incomplete Denylist https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78678

    Post summary

    The text announces an arbitrary file read vulnerability in GitPython versions prior to 3.1.59 due to an incomplete denylist, without mention of PoC, exploits, or patches.

    0000097
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitpython_projectgitpython-python-

Explore more