← All CVEs NewScan detects
high

CVE-2026-73620

GitPython argument injection via unguarded git option forwarding (IndexFile.checkout / TagReference.create)

Severity
high
Affected product
GitPython
Affected versions
GitPython < 3.1.57
Fixed in
GitPython 3.1.57
Added to NewScan
2026-08-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints GitPython from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-23 (D117's manifest question answered: /requirements.txt IS in version_tools._MANIFESTS and the PyPI name 'GitPython' joins by its own lowercase, so no alias entry was needed). This row covers the two ids of the 2026 batch that share fix 3.1.57 (GHSA-mhfq-f35q-x62m): CVE-2026-73620 itself (CVSS 8.1 - unsafe git options through IndexFile.checkout()/TagReference.create(), arbitrary file write/read) and CVE-2026-73619 (incomplete unsafe_git_archive_options denylist - arbitrary file read via Repo.archive). The REST of the batch is deliberately NOT claimed: CVE-2026-73624/73625 are fixed in 3.1.54 and CVE-2026-76217 in 3.1.58 - different bounds, so each needs its own row once its advisory range and severity are sourced, and a widened range here would flag patched builds. Library CVE, version-match only, reached through a served requirements.txt/Pipfile.lock pin.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →