<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 21:38:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00628</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00628</link>
      <description>bdu:2024-00628</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00628</guid>
    </item>
    <item>
      <title>BREW-cf2tf-CVE-2024-22190 — Untrusted search path under some conditions on Windows allows arbitrary code execution</title>
      <link>https://cve.radiocsirt.org/vuln/brew-cf2tf-cve-2024-22190</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: cf2tf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This issue exists because of an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Although GitPython often avoids executing programs found in an untrusted search path since 3.1.33, two situations remain where this still occurs. Either can allow arbitrary code execution under some circumstances.&lt;/p&gt;
&lt;p&gt;#### When a shell is used&lt;/p&gt;
&lt;p&gt;GitPython can be told to run `git` commands through a shell rather than as direct subprocesses, by passing `shell=True` to any method that accepts it, or by both setting `Git.USE_SHELL = True` and not passing `shell=False`. Then the Windows `cmd.exe` shell process performs the path search, and GitPython does not prevent that shell from finding and running `git` in the current directory.&lt;/p&gt;
&lt;p&gt;When GitPython runs `git` directly rather than through a shell, the GitPython process performs the path search, and currently omits the current directory by setting `NoDefaultCurrentDirectoryInExePath` in its own environment during the `Popen` call. Although the `cmd.exe` shell will honor this environment variable when present, GitPython does not currently pass it into the shell subprocess&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Furthermore, because GitPython sets the subprocess CWD to the root of a repository&amp;#39;s working tree…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: cf2tf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This issue exists because of an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Although GitPython often avoids executing programs found in an untrusted search path since 3.1.33, two situations remain where this still occurs. Either can allow arbitrary code execution under some circumstances.&lt;/p&gt;
&lt;p&gt;#### When a shell is used&lt;/p&gt;
&lt;p&gt;GitPython can be told to run `git` commands through a shell rather than as direct subprocesses, by passing `shell=True` to any method that accepts it, or by both setting `Git.USE_SHELL = True` and not passing `shell=False`. Then the Windows `cmd.exe` shell process performs the path search, and GitPython does not prevent that shell from finding and running `git` in the current directory.&lt;/p&gt;
&lt;p&gt;When GitPython runs `git` directly rather than through a shell, the GitPython process performs the path search, and currently omits the current directory by setting `NoDefaultCurrentDirectoryInExePath` in its own environment during the `Popen` call. Although the `cmd.exe` shell will honor this environment variable when present, GitPython does not currently pass it into the shell subprocess&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Furthermore, because GitPython sets the subprocess CWD to the root of a repository&amp;#39;s working tree…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-cf2tf-cve-2024-22190</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</link>
      <description>certfr-2024-avi-0145</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</guid>
    </item>
    <item>
      <title>EUVD-2026-161162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-161162</link>
      <description>EUVD-2026-161162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-161162</guid>
    </item>
    <item>
      <title>fkie_cve-2024-22190</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22190</link>
      <description>&lt;p&gt;GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-22190</guid>
    </item>
    <item>
      <title>GHSA-2mqj-m65w-jghx — Untrusted search path under some conditions on Windows allows arbitrary code execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2mqj-m65w-jghx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This issue exists because of an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Although GitPython often avoids executing programs found in an untrusted search path since 3.1.33, two situations remain where this still occurs. Either can allow arbitrary code execution under some circumstances.&lt;/p&gt;
&lt;p&gt;#### When a shell is used&lt;/p&gt;
&lt;p&gt;GitPython can be told to run `git` commands through a shell rather than as direct subprocesses, by passing `shell=True` to any method that accepts it, or by both setting `Git.USE_SHELL = True` and not passing `shell=False`. Then the Windows `cmd.exe` shell process performs the path search, and GitPython does not prevent that shell from finding and running `git` in the current directory.&lt;/p&gt;
&lt;p&gt;When GitPython runs `git` directly rather than through a shell, the GitPython process performs the path search, and currently omits the current directory by setting `NoDefaultCurrentDirectoryInExePath` in its own environment during the `Popen` call. Although the `cmd.exe` shell will honor this environment variable when present, GitPython does not currently pass it into the shell subprocess&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Furthermore, because GitPython sets the subprocess CWD to the root of a repository&amp;#39;s working tree…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: GitPython&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;This issue exists because of an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Although GitPython often avoids executing programs found in an untrusted search path since 3.1.33, two situations remain where this still occurs. Either can allow arbitrary code execution under some circumstances.&lt;/p&gt;
&lt;p&gt;#### When a shell is used&lt;/p&gt;
&lt;p&gt;GitPython can be told to run `git` commands through a shell rather than as direct subprocesses, by passing `shell=True` to any method that accepts it, or by both setting `Git.USE_SHELL = True` and not passing `shell=False`. Then the Windows `cmd.exe` shell process performs the path search, and GitPython does not prevent that shell from finding and running `git` in the current directory.&lt;/p&gt;
&lt;p&gt;When GitPython runs `git` directly rather than through a shell, the GitPython process performs the path search, and currently omits the current directory by setting `NoDefaultCurrentDirectoryInExePath` in its own environment during the `Popen` call. Although the `cmd.exe` shell will honor this environment variable when present, GitPython does not currently pass it into the shell subprocess&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Furthermore, because GitPython sets the subprocess CWD to the root of a repository&amp;#39;s working tree…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2mqj-m65w-jghx</guid>
    </item>
    <item>
      <title>gsd-2024-22190</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-22190</link>
      <description>gsd-2024-22190</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-22190</guid>
    </item>
    <item>
      <title>PYSEC-2024-4</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-4</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-22190</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22190</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:24.04:LTS: python-git, Ubuntu:25.10: python-git, Ubuntu:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:24.04:LTS: python-git, Ubuntu:25.10: python-git, Ubuntu:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an untrusted repository. This issue has been patched in version 3.1.41.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22190</guid>
    </item>
  </channel>
</rss>
