GitPython has disclosed seven vulnerabilities affecting multiple versions of the widely used Python library, exposing CI/CD and other automation environments to supply-chain risk. The most severe issue, CVE-2026-73625 (CVSS 8.8), allows remote code execution by bypassing check_unsafe_options and smuggling unsafe Git options through crafted keyword arguments, enabling arbitrary command execution through parameters such as --upload-pack. Affected methods include clone_from, fetch, pull, push, ls_remote, iter_commits, blame, and archive, according to public advisories and CVE records.
The broader disclosure also includes CVE-2026-73622, which can leak secrets by expanding environment variables in attacker-controlled URLs and writing them into .git/config or .gitmodules, as well as CVE-2026-73620 and CVE-2026-73624, which permit arbitrary file read or overwrite through unsafe option forwarding in functions such as IndexFile.checkout(), TagReference.create(), and Diffable.diff(). GitHub advisories further describe related issues involving local file disclosure, git-directory creation outside the destination, unsafe configuration handling, and hook or template abuse. Fixes were released across versions 3.1.54, 3.1.55, 3.1.56, and 3.1.57, with reports indicating that upgrading to GitPython 3.1.57 remediates all seven CVEs; no active exploitation was reported at publication time.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
ThreatAft reported that GitPython disclosed seven vulnerabilities affecting multiple versions, framing the issue as a supply-chain risk for Python CI/CD environments. The report states that fixes were spread across versions 3.1.54, 3.1.56, and 3.1.57, and that upgrading to 3.1.57 remediates all seven CVEs.
A vulnerability entry for CVE-2026-73625 was published describing a remote code execution flaw in GitPython's check_unsafe_options guard. The issue affects versions before 3.1.54 and allows arbitrary OS command execution via smuggled git options such as --upload-pack.
A vulnerability entry for CVE-2026-73624 was disclosed for GitPython before 3.1.54, affecting the Diffable.diff method. The flaw allows attackers to pass --output through kwargs or parameters and overwrite attacker-chosen files with patch content.
A vulnerability entry for CVE-2026-73622 was disclosed for GitPython before 3.1.55, describing environment variable expansion in Remote.create() and Submodule.add(). The flaw can expose secrets by expanding environment-variable references into .git/config or .gitmodules and sending them to attacker-controlled hosts.
A vulnerability entry for CVE-2026-73620 was disclosed describing improper guarding of git option forwarding in IndexFile.checkout() and TagReference.create(). The issue affects GitPython versions earlier than 3.1.57 and can enable arbitrary file overwrite via --prefix or arbitrary file read via -F.
GitHub Security Advisories published five additional GitPython advisories on issues including .gitmodules include directive abuse, injected git-config directives enabling RCE, unsafe clone options, and arbitrary file read flaws. The advisories listed include GHSA-7833-fr7j-v32q, GHSA-284h-m62q-gf8w, GHSA-8mcc-hrx5-hvxc, GHSA-5xxx-qhh7-9287, and GHSA-3wxw-xv34-2frg.
GitHub Security Advisories published four GitPython advisories covering arbitrary file read, arbitrary command execution, arbitrary file overwrite, and an unsafe option guard bypass. The listed advisories include GHSA-hh9p-6wh2-4mfc, GHSA-9rj7-rf2p-w77r, GHSA-4gmw-gg2m-w46p, and GHSA-wvpp-8hx9-p66j.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcethreataft.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.