Threats Tagged 'ghsa-539m-9xh6-q6rr'
View all threats tagged with 'ghsa-539m-9xh6-q6rr'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-539m-9xh6-q6rr'
Click on any threat for detailed analysis and mitigation recommendations
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive() 0 GitPython's Repo.archive() method uses a denylist to block unsafe git archive options, but this denylist is incomplete. Specifically, the options --add-file and --add-virtual-file, which allow reading arbitrary files from the filesystem and injecting arbitrary content into archives, are not blocked. This enables an attacker who can control the options passed to Repo.archive() to read arbitrary files with the privileges of the running process. The vulnerability does not allow code execution but can lead to sensitive file disclosure. A patch is available that extends the denylist to cover these options or implements a safer allowlist approach. Join the discussion | GCVE Database | 08/03/2026, 20:14:28 UTC Added: 08/03/2026, 21:21:22 UTC |
Showing 1 to 1 of 1 result