Known vulnerabilities in GitPython

Software: GitPython
Software CPE: cpe:2.3:a:gitpython-developers:gitpython:*:*:*:*:*:*:*:*
Total vulnerabilities: 31
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitPython GitPython is affected by 31 known vulnerabilities: 4 high, 13 medium, 14 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140975 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 High
No
No
3.1.58 05.08.2026 SB2026080540
#VU140974 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-74 Medium
No
No
3.1.58 05.08.2026 SB2026080540
#VU140973 - Argument Injection or Modification
CWE-88 Medium
No
No
3.1.58 05.08.2026 SB2026080540
#VU140972 - Argument Injection or Modification
CWE-88 Medium
No
No
3.1.58 05.08.2026 SB2026080540
#VU140971 - Argument Injection or Modification
CWE-88 Low
No
No
3.1.58 05.08.2026 SB2026080540
#VU140970 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
3.1.58 05.08.2026 SB2026080540
#VU140587 - External Control of File Name or Path
CWE-73 Medium
No
No
3.1.57 31.07.2026 SB2026073119
#VU140588 - External Control of File Name or Path
CWE-73 Low
No
No
3.1.57 31.07.2026 SB2026073119
#VU140585 - External Control of File Name or Path
CWE-73 Low
No
No
3.1.57 31.07.2026 SB2026073119
#VU140586 - Server-Side Request Forgery (SSRF)
CWE-918 Low
No
No
3.1.57 31.07.2026 SB2026073119
#VU140584 - Argument Injection or Modification
CWE-88 Low
No
No
3.1.56 31.07.2026 SB2026073118
#VU140582 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
3.1.55 31.07.2026 SB2026073117
#VU139092 - Argument Injection or Modification
CWE-88 Medium
No
No
3.1.54 22.07.2026 SB2026072243
#VU139091 - Argument Injection or Modification
CWE-88 Medium
No
No
3.1.54 22.07.2026 SB2026072243
#VU139090 - Incomplete List of Disallowed Inputs
CWE-184 Low
No
No
3.1.54 22.07.2026 SB2026072243
#VU139089 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-74 Medium
No
No
3.1.53 22.07.2026 SB2026072242
#VU139088 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
3.1.52 22.07.2026 SB2026072241
#VU139087 - Incomplete List of Disallowed Inputs
CWE-184 Medium
No
No
3.1.51 22.07.2026 SB2026072240
#VU139086 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Low
No
No
3.1.51 22.07.2026 SB2026072240
#VU139085 - Argument Injection or Modification
CWE-88 Low
No
No
3.1.51 22.07.2026 SB2026072240


Showing elements 1 - 20 out of 31