Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-24439

33
FAUCET Score

CVE-2022-24439 is a critical Remote Code Execution (RCE) vulnerability affecting all versions of the GitPython package, as well as various Debian and Fedora distributions. It stems from insufficient input validation when handling remote URLs in the clone command, allowing for the injection of malicious code. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over a network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.1.30CPE matchmatch criteria
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
5.38%
Probability of exploitation in next 30 days
EPSS Percentile
91.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0538 is in the 86th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

pippatch availablevia ghsa
Product: GitPythonFixed in: 3.1.30
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.13 for RHEL 8Fixed in: python-gitpython-0:3.1.32-1.el8pc
View patch
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python-gitpython
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: GitPython
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: GitPython
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: GitPython
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 17.0Fixed in: GitPython

Vendor Advisories (2)

pipGHSA-hcpj-qp55-gfphcritical

GitPython vulnerable to Remote Code Execution due to improper user input validation

Dec 6, 2022
redhatCVE-2022-24439Moderate

GitPython: improper user input validation leads into a RCE

Dec 5, 2022

References

lists.debian.org / debian-lts-announce/2024/10/msg00030.html
github.com / gitpython-developers/GitPython/blob/bec61576ae75803bc4e60d8de7a629c194313d1c/git/repo/base.py%23L1249
Broken Link
lists.debian.org / debian-lts-announce/2023/07/msg00024.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/AV5DV7GBLMOZT7U3Q4TDOJO5R6G3V6GH
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IKMVYKLWX62UEYKAN64RUZMOIAMZM5JN
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PF6AXUTC5BO7L2SBJMCVKJSPKWY52I5R
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SJHN3QUXPJIMM6SULIR3PR34UFWRAE7X
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202311-01
Third Party Advisory
security.snyk.io / vuln/SNYK-PYTHON-GITPYTHON-3113858
ExploitThird Party Advisory