---
title: 'Topic: gitpython'
canonical_url: https://portal.chinng-lab-srv.dev/topics/gitpython.md
content_kind: topic
updated_at: '2026-08-02T07:21:57Z'
---

# Topic: gitpython

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/gitpython.md
- Last updated: 2026-08-02T07:21:57Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=gitpython
- MCP: portal_search(q="gitpython")

## Related categories

- security/library

## Related entities

- GitPython
- Latvia
- GitHub
- Chainguard
- Incomplete_Aesthetics
- Gotosocial_injection
- New edge AI module based on Blackwell architecture that enables humaninoid robot mass production
- ElectricVehicle
- PyPI
- Aviation Wire
- config.yaml
- HashTag
- Command and Conquer Generals
- options
- infraestructura de salud check

## Latest articles

- [GHSA-94p4-4cq8-9g67: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-df0150.md): GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
- [GHSA-r9mr-m37c-5fr3: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution](https://portal.chinng-lab-srv.dev/security/library/security-20260725-d05ab6.md): GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
- [GHSA-6p8h-3wgx-97gf: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks](https://portal.chinng-lab-srv.dev/security/library/security-20260725-96fd04.md): GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
- [GHSA-fjr4-x663-mwxc: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-aa9760.md): GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
- [GHSA-3rp5-jjmw-4wv2: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-bc7367.md): GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
- [CVE-2026-67322: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL](https://portal.chinng-lab-srv.dev/security/library/security-20260722-bdbe76.md): GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
- [CVE-2026-67323: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`](https://portal.chinng-lab-srv.dev/security/library/security-20260722-f9f263.md): GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
- [CVE-2026-67325: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist](https://portal.chinng-lab-srv.dev/security/library/security-20260722-96cbaf.md): GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
- [CVE-2026-67326: GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath](https://portal.chinng-lab-srv.dev/security/library/security-20260711-fad306.md): GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
- [CVE-2026-44244 — gitpython](https://portal.chinng-lab-srv.dev/security/library/security-20260714-6a196b.md): GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitP…
- [CVE-2026-44243 — gitpython](https://portal.chinng-lab-srv.dev/security/library/security-20260714-452cd1.md): GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application…
- [CVE-2026-42215 — gitpython](https://portal.chinng-lab-srv.dev/security/library/security-20260714-a28fde.md): GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by…
- [CVE-2026-42284 — gitpython](https://portal.chinng-lab-srv.dev/security/library/security-20260714-3d4f5e.md): GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)…
- [CVE-2026-44244: GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath](https://portal.chinng-lab-srv.dev/security/library/security-20260711-f47f64.md): GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
- [CVE-2026-44243: GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository](https://portal.chinng-lab-srv.dev/security/library/security-20260711-5bcc98.md): GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
- [CVE-2026-42215: GitPython has Command Injection via Git options bypass](https://portal.chinng-lab-srv.dev/security/library/security-20260711-603762.md): GitPython has Command Injection via Git options bypass
- [CVE-2026-42284: GitPython: Unsafe option check validates multi_options before shlex.split transformation](https://portal.chinng-lab-srv.dev/security/library/security-20260711-70130c.md): GitPython: Unsafe option check validates multi_options before shlex.split transformation
