CVE-2026-73620
GitPython argument injection via unguarded git option forwarding (IndexFile.checkout / TagReference.create)
- Severity
- high
- Affected product
- GitPython
- Affected versions
- GitPython < 3.1.57
- Fixed in
- GitPython 3.1.57
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints GitPython from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-23 (D117's manifest question answered: /requirements.txt IS in version_tools._MANIFESTS and the PyPI name 'GitPython' joins by its own lowercase, so no alias entry was needed). This row covers the two ids of the 2026 batch that share fix 3.1.57 (GHSA-mhfq-f35q-x62m): CVE-2026-73620 itself (CVSS 8.1 - unsafe git options through IndexFile.checkout()/TagReference.create(), arbitrary file write/read) and CVE-2026-73619 (incomplete unsafe_git_archive_options denylist - arbitrary file read via Repo.archive). The REST of the batch is deliberately NOT claimed: CVE-2026-73624/73625 are fixed in 3.1.54 and CVE-2026-76217 in 3.1.58 - different bounds, so each needs its own row once its advisory range and severity are sourced, and a widened range here would flag patched builds. Library CVE, version-match only, reached through a served requirements.txt/Pipfile.lock pin.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →