<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:31:35.041312+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11883</id>
    <title>bdu:2026-11883</title>
    <updated>2026-10-02T14:31:36.047004+00:00</updated>
    <content>bdu:2026-11883</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-73625</id>
    <title>BREW-aider-CVE-2026-73625 — GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command ex…</title>
    <updated>2026-10-02T14:31:36.047068+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>## Summary
GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling an option token inside the VALUE of a single-character kwarg. In the default `allow_unsafe_options=False` configuration this yields arbitrary command execution via `--upload-pack`.</p>
<p>## Root Cause
The guard builds its candidate option list from kwarg KEYS only: `_option_candidates([], {"n":"--upload-pack=&lt;cmd&gt;"})` returns `['-n']` (cmd.py:1042-1046 derives the candidate from the key, never the value). `-n` is not on the denylist, so `check_unsafe_options` passes. But `transform_kwarg('n', value, split_single_char_options=True)` (cmd.py:1600-1606) emits **two** argv tokens `['-n', '--upload-pack=&lt;cmd&gt;']`. git then parses the second token as `--upload-pack` and executes the attacker-supplied command. The guard never inspects the value that becomes a separate argv token.</p>
<p>## Impact
Arbitrary OS command execution as the host process (via `--upload-pack`) in the default configuration, affecting all guarded methods since they all build candidates through the name-only `_option_candidates`.</p>
<p>## Proof of Concept
```python
from git import Repo
Repo.clone_from(bare_repo, out_dir, n="--upload-pack=touch /tmp/ACE;git-upload-pack")
# /tmp/ACE created -&gt; ACE. Direct-name form upload_pack="..." is correctly BLOCKED.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-73625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352926</id>
    <title>EUVD-2026-352926</title>
    <updated>2026-10-02T14:31:36.047282+00:00</updated>
    <content>EUVD-2026-352926</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73625</id>
    <title>fkie_cve-2026-73625</title>
    <updated>2026-10-02T14:31:36.047308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pjjh-f8rp-rjv3</id>
    <title>GHSA-pjjh-f8rp-rjv3</title>
    <updated>2026-10-02T14:31:36.047363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pjjh-f8rp-rjv3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3699</id>
    <title>OESA-2026-3699 — python-GitPython security update</title>
    <updated>2026-10-02T14:31:36.047432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-GitPython</p>
<p>GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.

Security Fix(es):</p>
<p>GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.(CVE-2026-73619)</p>
<p>GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.(CVE-2026-73620)</p>
<p>GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to &amp;apos;git rev-list&amp;apos; without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=&amp;lt;path&amp;gt;, causing &amp;apos;git rev-list --output=&amp;lt;path&amp;gt;&amp;apos; to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process&amp;apos;s privilege level (no content control, 0-byte truncation).(CVE-2026-73621)</p>
<p>GitPython before 3.1.55 fails to disable env…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1</id>
    <title>openSUSE-SU-2026:21874-1 — Security update for python-GitPython</title>
    <updated>2026-10-02T14:31:36.047491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-GitPython</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3953</id>
    <title>PYSEC-2026-3953</title>
    <updated>2026-10-02T14:31:36.047524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:63385</id>
    <title>RHSA-2026:63385 — Red Hat Security Advisory: Satellite 6.19.4 Async Update</title>
    <updated>2026-10-02T14:31:36.047543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332) aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks GitPython: GitPython: Arbitrary code execution via improper validation of clone options GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding gitpython: GitPython: Information disclosure via environment variable expansion in URL handling gitpython: GitPython: Remote Code Execution via malicious Git template gitpython: GitPython: Arbitrary File Overwrite via improper git option validation gitpython: GitPython: Remote Code Exec…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:63385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73625</id>
    <title>UBUNTU-CVE-2026-73625</title>
    <updated>2026-10-02T14:31:36.047603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git</p>
<p>GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73625"/>
  </entry>
</feed>
