Arbitrary File Read Vulnerability in GitPython by GitPython Developers
CVE-2026-78679
7.1HIGH
What is CVE-2026-78679?
An arbitrary file read vulnerability has been identified in GitPython prior to version 3.1.59. This issue occurs in the TagReference.create() function, where an attacker can exploit a positional reference parameter to bypass security safeguards. By supplying a reference value formatted as --file=, an attacker could gain access to unauthorized files, with the file contents returned within the annotated tag message. This presents a risk of sensitive data exposure, necessitating immediate attention and updates to the affected versions.
Affected Version(s)
GitPython 0 < 3.1.59
GitPython 3.1.59
