CVE-2026-67325EPSS p82.0%
CVE-2026-67325CVE-2026-67325
gitpython_project / gitpython
Description
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.21% probability of exploitation · percentile 82.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-03 |