VDB
Sign up
HIGH8.8

PYSEC-2026-2160

Quick fix

PYSEC-2026-2160 — gitpython: upgrade to the fixed version with the command below.

pip install --upgrade 'gitpython>=3.1.47'

Details

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/gitpython
Introduced in: 3.1.30Fixed in: 3.1.47
Fixpip install --upgrade 'gitpython>=3.1.47'

References