<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T17:04:01.926153+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05185</id>
    <title>bdu:2023-05185</title>
    <updated>2026-10-09T17:04:01.939517+00:00</updated>
    <content>bdu:2023-05185</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-checkov-cve-2023-40590</id>
    <title>BREW-checkov-CVE-2023-40590 — GitPython untrusted search path on Windows systems leading to arbitrary code execution</title>
    <updated>2026-10-09T17:04:01.939551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: checkov</p>
<p>### Summary</p>
<p>When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment (see big warning in https://docs.python.org/3/library/subprocess.html#popen-constructor). GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`.</p>
<p>### Details</p>
<p>This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo.</p>
<p>The execution of the `git` command happens in</p>
<p>https://github.com/gitpython-developers/GitPython/blob/1c8310d7cae144f74a671cbe17e51f63a830adbf/git/cmd.py#L277</p>
<p>https://github.com/gitpython-developers/GitPython/blob/1c8310d7cae144f74a671cbe17e51f63a830adbf/git/cmd.py#L983-L996</p>
<p>And there are other commands executed that should probably be aware of this problem.</p>
<p>### PoC</p>
<p>On a Windows system, create a `git.exe` or `git` executable in any directory, and import or run GitPython from that directory</p>
<p>```
python -c "import git"
```</p>
<p>The git executable from the current directory will be run.</p>
<p>### Impact</p>
<p>An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands.</p>
<p>### Possible solutions
 
- Default to an absolute path for the git program on W…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-checkov-cve-2023-40590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-190882</id>
    <title>EUVD-2026-190882</title>
    <updated>2026-10-09T17:04:01.939610+00:00</updated>
    <content>EUVD-2026-190882</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-190882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-40590</id>
    <title>fkie_cve-2023-40590</title>
    <updated>2026-10-09T17:04:01.939625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like `C:\\Program Files\\Git\\cmd\\git.EXE` (default git path installation). 2: Require users to set the `GIT_PYTHON_GIT_EXECUTABLE` environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the `GIT_PYTHON_GIT_EXECUTABLE` env var to an absolute path. 4: Resolve the executable manually by only looking into the `PATH` environment variable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-40590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wfm5-v35h-vwf4</id>
    <title>GHSA-wfm5-v35h-vwf4 — GitPython untrusted search path on Windows systems leading to arbitrary code execution</title>
    <updated>2026-10-09T17:04:01.939657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: GitPython</p>
<p>### Summary</p>
<p>When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment (see big warning in https://docs.python.org/3/library/subprocess.html#popen-constructor). GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`.</p>
<p>### Details</p>
<p>This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo.</p>
<p>The execution of the `git` command happens in</p>
<p>https://github.com/gitpython-developers/GitPython/blob/1c8310d7cae144f74a671cbe17e51f63a830adbf/git/cmd.py#L277</p>
<p>https://github.com/gitpython-developers/GitPython/blob/1c8310d7cae144f74a671cbe17e51f63a830adbf/git/cmd.py#L983-L996</p>
<p>And there are other commands executed that should probably be aware of this problem.</p>
<p>### PoC</p>
<p>On a Windows system, create a `git.exe` or `git` executable in any directory, and import or run GitPython from that directory</p>
<p>```
python -c "import git"
```</p>
<p>The git executable from the current directory will be run.</p>
<p>### Impact</p>
<p>An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands.</p>
<p>### Possible solutions
 
- Default to an absolute path for the git program on W…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wfm5-v35h-vwf4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-40590</id>
    <title>gsd-2023-40590</title>
    <updated>2026-10-09T17:04:01.939700+00:00</updated>
    <content>gsd-2023-40590</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-40590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13207-1</id>
    <title>openSUSE-SU-2024:13207-1 — python310-GitPython-3.1.34.1693646983.2a2ae77-1.1 on GA media</title>
    <updated>2026-10-09T17:04:01.939712+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-GitPython-3.1.34.1693646983.2a2ae77-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13207-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-161</id>
    <title>PYSEC-2023-161</title>
    <updated>2026-10-09T17:04:01.939729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like `C:\\Program Files\\Git\\cmd\\git.EXE` (default git path installation). 2: Require users to set the `GIT_PYTHON_GIT_EXECUTABLE` environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the `GIT_PYTHON_GIT_EXECUTABLE` env var to an absolute path. 4: Resolve the executable manually by only looking into the `PATH` environment variable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-161"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-40590</id>
    <title>UBUNTU-CVE-2023-40590</title>
    <updated>2026-10-09T17:04:01.939756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:22.04:LTS: python-git</p>
<p>GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like `C:\\Program Files\\Git\\cmd\\git.EXE` (default git path installation). 2: Require users to set the `GIT_PYTHON_GIT_EXECUTABLE` environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the `GIT_PYTHON_GIT_EXECUTABLE` env var to an absolute path. 4: Resolve the executable manually by only looking into the `PATH` environment variable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-40590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2428</id>
    <title>WID-SEC-W-2023-2428 — SaltStack Salt: Mehre Schwachstellen</title>
    <updated>2026-10-09T17:04:01.939788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann eine Schwachstelle in SaltStack Salt ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2428"/>
  </entry>
</feed>
