GitPython is a widely embedded Python library for interacting with Git repositories, and despite a single-product focus, its presence across development toolchains and automation platforms amplifies the impact of its vulnerabilities. The vendor's disclosures skew strongly toward critical-severity outcomes and concentrate on input-handling and code-injection weaknesses—including path traversal, untrusted search paths, code injection, and argument injection—that are characteristic of a command-wrapping library operating on user-supplied repository data. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitpython Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42284CRITICAL GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ". | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-42215HIGH GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and | May 7, 2026 | 8.8 | 35 | NO | NO |
CVE-2022-24439CRITICAL All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remot | Dec 6, 2022 | 9.8 | 33 | NO | NO |
CVE-2026-44244HIGH GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating | May 7, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-44243HIGH GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path | May 7, 2026 | 7.1 | 28 | NO | NO |
CVE-2023-40590HIGH GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH envi | Aug 28, 2023 | 7.8 | 25 | NO | NO |
CVE-2023-40267CRITICAL GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. | Aug 11, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-22190HIGH GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses | Jan 11, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-41040MEDIUM GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the n | Aug 30, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitpython Project.
Media articles that mention a CVE ID that affects a product developed by Gitpython Project — matched by CVE ID, not by vendor name.