Vendor
high
advisory
Command Injection Vulnerability in GitPython
1 TTP 1 CVEGitPython versions prior to 3.1.51 are vulnerable to command injection because the library's security blocklist fails to account for Git command-line option abbreviation, allowing attackers to execute arbitrary commands.
GitPython
vulnerability
command-injection
python
1t
1c
high
advisory
GitPython Improper Input Validation Leads to Command Injection
1 TTP 1 CVEGitPython version 3.1.50 contains an input validation vulnerability that allows attackers to bypass security gates by using joined short-option forms, potentially leading to arbitrary command execution during repository cloning.
GitPython
cve-2026-67324
command-injection
python
1t
1c