Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/gitpython

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

Join the discussion

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.

Join the discussion

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

Join the discussion

GitPython versions before 3.1.59 contain an arbitrary file read vulnerability in the TagReference.create() function. This flaw allows an attacker to bypass the unsafe option guard by supplying a specially crafted positional reference parameter such as --file=<path>, enabling reading of arbitrary files. The contents of these files are then returned in the annotated tag message.

Join the discussion

GitPython versions before 3.1.59 contain a vulnerability where an incomplete denylist in the unsafe_git_revision_options guard allows attackers to pass certain options to the Repo.blame() method. This flaw permits reading arbitrary files by supplying revision values such as --contents=/etc/passwd, which leaks file contents through the blame result.

Join the discussion

GitPython versions prior to 3.1.59 contain a path traversal vulnerability that allows attackers to create arbitrary git directories outside the intended clone destination. This occurs because the --separate-git-dir option is omitted from unsafe_git_clone_options, enabling attackers to redirect repository metadata to attacker-controlled filesystem paths via the separate_git_dir parameter in cloning functions.

Join the discussion

GitPython versions prior to 3.1.59 contain a vulnerability where multi-line git-config values are improperly re-serialized during write operations. This flaw allows attackers to inject new git directives, such as core.hooksPath, by embedding newlines in config files. Exploitation can lead to arbitrary code execution through hook invocation.

Join the discussion

GitPython versions prior to 3.1.59 contain a vulnerability where the merge_includes feature is not disabled when parsing .gitmodules files. This allows attackers to craft malicious .gitmodules files with include directives referencing arbitrary local file paths. When the repository's submodules are accessed, an exception is raised that leaks the first line of the targeted file in the error message.

Join the discussion

GitPython versions before 3.1.58 contain a remote code execution vulnerability in the Repo.init function. This flaw arises because unsafe git options are forwarded without validation, allowing attackers to supply a malicious template parameter. The malicious template can point to a directory with crafted git hooks that execute arbitrary code during git operations on the initialized repository.

Join the discussion

GitPython versions before 3.1.58 contain a path traversal vulnerability due to improper validation of submodule names in .gitmodules files. This flaw allows attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory by using traversal sequences in submodule names. The vulnerability is rated high severity with a CVSS score of 8.4.

Join the discussion

Showing 1 to 10 of 45 results

Filters:Package: pkg:pypi/gitpython
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses