Known vulnerabilities in python-GitPython

Vendor: openEuler
Software CPE: cpe:2.3:o:openeuler:python-gitpython:*:*:*:*:*:openeuler:*:*
Total vulnerabilities: 13
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting python-GitPython python-GitPython is affected by 13 known vulnerabilities: 2 high, 5 medium, 6 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140970 - Exposure of sensitive information to an unauthorized actor
CVE-2026-76217
CWE-200 Low
No
No
3.1.32-4 05.08.2026 SB2026080540
SB20260914117
SB20260914118
#VU139089 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-69097
CWE-74 Medium
No
No
3.1.57-1 22.07.2026 SB2026072242
SB20260914114
SB20260914115
and 1 more
#VU139088 - Exposure of sensitive information to an unauthorized actor
CVE-2026-67322
CWE-200 Medium
No
No
3.1.52-1 22.07.2026 SB2026072241
SB20260914111
SB20260914112
and 1 more
#VU139087 - Incomplete List of Disallowed Inputs
CVE-2026-67325
CWE-184 Medium
No
No
3.1.52-1 22.07.2026 SB2026072240
SB20260914111
SB20260914112
and 1 more
#VU139086 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-67324
CWE-78 Low
No
No
3.1.52-1 22.07.2026 SB2026072240
SB20260914111
SB20260914112
and 1 more
#VU139084 - Command injection
CVE-2026-67323
CWE-77 Low
No
No
3.1.52-1 22.07.2026 SB2026072240
SB20260914111
SB20260914112
and 1 more
#VU131003 - Improper input validation
CVE-2026-67326
CWE-20 Medium
No
No
3.1.52-1 11.05.2026 SB2026051197
SB20260914111
SB20260914112
and 1 more
#VU131002 - Improper input validation
CVE-2026-44244
CWE-20 Low
No
No
3.1.49-1 11.05.2026 SB2026051196
SB2026061946
SB2026061947
and 2 more
#VU128348 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-44243
CWE-22 Low
No
No
3.1.49-1 28.04.2026 SB2026042875
SB2026061946
SB2026061947
and 2 more
#VU128120 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-42215
CWE-78 Medium
No
No
3.1.49-1 27.04.2026 SB2026042793
SB2026050640
SB2026050641
and 8 more
#VU81056 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-41040
CWE-22 Low
No
No
3.1.32-2 22.09.2023 SB2023092227
SB2023102621
SB2023110908
and 6 more
#VU79631 - Improper input validation
CVE-2023-40267
CWE-20 High
No
No
3.1.32-1 16.08.2023 SB2023081631
SB20230821206
SB20230821207
and 9 more
#VU79630 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24439
CWE-94 High
No
No
3.1.32-1 16.08.2023 SB2022120650
SB20230816235
SB2023082070
and 12 more