CVE-2026-78678EPSS p33.3%
CVE-2026-78678CVE-2026-78678
gitpython_project / gitpython
Description
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to the caller.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.41% probability of exploitation · percentile 33.3% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-02 |