Improper Validation of Specified Type of Input in GitPython - #VU152988
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject unsafe command-line options.
The vulnerability exists due to improper validation of specified input type in Repo.merge_base when forwarding caller-controlled revision arguments and keyword arguments to git merge-base. A remote attacker can supply unsafe keyword arguments to inject unsafe command-line options.
User interaction is required. Non-128 Git command errors are converted to an empty result.