Gitpython
Vendor:
First CVE: Dec 6, 2022 · Active for 3 years
9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gitpython over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2022
3 years ago
Most Recent CVE
May 7, 2026
78 days ago
CVE Severity & Scoring
Gitpython9 CVEs
11%
56%
33%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (44.4%)
Network5 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42284CRITICAL GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ". | May 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-42215HIGH GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and | May 7, 2026 | 8.8 | 35 | NO | NO |
CVE-2022-24439CRITICAL All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remot | Dec 6, 2022 | 9.8 | 33 | NO | NO |
CVE-2026-44244HIGH GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating | May 7, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-44243HIGH GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path | May 7, 2026 | 7.1 | 28 | NO | NO |
CVE-2023-40590HIGH GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH envi | Aug 28, 2023 | 7.8 | 25 | NO | NO |
CVE-2023-40267CRITICAL GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. | Aug 11, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-22190HIGH GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses | Jan 11, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-41040MEDIUM GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the n | Aug 30, 2023 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Gitpython
Top CWEs
Versions
No cataloged versions.