VDB

CVE-2026-73624

CVE-2026-73624 PUBLISHED CVSS 7.2 HIGH

Reported by VulnCheck · Published August 13, 2026

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

Risk Scores

CVSS 4.0
7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
gitpython-developersGitPython0, 3.1.54
gitpython_projectgitpython0
gitpython-developersGitPython0, 3.1.54, 0

Timeline

  • Aug 13, 2026 Coalition ESS Score
  • Aug 13, 2026 CVE Published
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 4, 2026 Distribution Patch
  • Sep 4, 2026 Security Advisory
  • Sep 5, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 CVE Updated
  • Sep 10, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›