GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.
References
| Link | Resource |
|---|---|
| https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48 | Patch Release Notes |
| https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 | Exploit Mitigation Vendor Advisory |
| https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 | Exploit Mitigation Vendor Advisory |
Configurations
History
07 May 2026, 21:12
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48 - Patch, Release Notes | |
| References | () https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 - Exploit, Mitigation, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
| CPE | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* | |
| First Time |
Gitpython Project gitpython
Gitpython Project |
07 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-fcxq-7j24 - |
07 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 19:16
Updated : 2026-05-07 21:12
NVD link : CVE-2026-44243
Mitre link : CVE-2026-44243
CVE.ORG link : CVE-2026-44243
JSON object : View
Products Affected
gitpython_project
- gitpython
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
