CVE-2026-44243

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*

History

07 May 2026, 21:12

Type Values Removed Values Added
References () https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48 - () https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48 - Patch, Release Notes
References () https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 - () https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 - Exploit, Mitigation, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CPE cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
First Time Gitpython Project gitpython
Gitpython Project

07 May 2026, 20:16

Type Values Removed Values Added
References () https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 - () https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 -

07 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 19:16

Updated : 2026-05-07 21:12


NVD link : CVE-2026-44243

Mitre link : CVE-2026-44243

CVE.ORG link : CVE-2026-44243


JSON object : View

Products Affected

gitpython_project

  • gitpython
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')