VDB
CVE-2026-73624
CVE-2026-73624
PUBLISHED
CVSS 7.2 HIGH
Reported by VulnCheck · Published August 13, 2026
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.
Risk Scores
CVSS 4.0
7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gitpython-developers | GitPython | 0, 3.1.54 |
| gitpython_project | gitpython | 0 |
| gitpython-developers | GitPython | 0, 3.1.54, 0 |
Timeline
- Aug 13, 2026 Coalition ESS Score
- Aug 13, 2026 CVE Published
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 4, 2026 Distribution Patch
- Sep 4, 2026 Security Advisory
- Sep 5, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 9, 2026 CVE Updated
- Sep 10, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-fjr4-x663-mwxc) vendor-advisory
- VulnCheck Advisory: GitPython before 3.1.54 Arbitrary File Overwrite via diff third-party-advisory