Improper Validation of Specified Type of Input in GitPython - #VU152989
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject unsafe command-line options.
The vulnerability exists due to improper validation of specified input type in IndexFile.move when forwarding caller-controlled keyword arguments to git mv. A remote attacker can supply unsafe keyword arguments to inject unsafe command-line options.
User interaction is required.