CPE
GitPython versions up to 3.1.59 are vulnerable to an arbitrary code execution flaw where malicious tracked repository content is misidentified as a Git directory, causing hooks to execute during standard repository operations.