Loading market data...
← Back to CVE feed

CVE-2026-44243

HIGH CVSS 7.1 View on NVD ↗

Description

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected Products

gitpython_project/gitpython
Published: May 07, 2026 19:16 UTC Modified: May 07, 2026 21:12 UTC