Arbitrary File Overwrite Vulnerability in GitPython by GitPython Developers
CVE-2026-73624
7.2HIGH
What is CVE-2026-73624?
GitPython versions prior to 3.1.54 include a vulnerability within the Diffable.diff method, where insufficient validation of git options passed via kwargs permits attackers to exploit the --output argument. This flaw allows the malicious input of file paths, resulting in the potential for attackers to overwrite files at the system's process privilege level, posing a significant security risk.
Affected Version(s)
GitPython 0 < 3.1.54
GitPython 3.1.54
