{"id":"MGASA-2026-0372","summary":"Updated python-gitpython packages fix security vulnerabilities","details":"CVE-2023-40267 GitPython before 3.1.32 does not block insecure non-multi\noptions in clone and clone_from. NOTE: this issue exists because of an\nincomplete fix for CVE-2022-24439.\nCVE-2023-41040 In order to resolve some git references, GitPython reads\nfiles from the `.git` directory, in some places the name of the file\nbeing read is provided by the user, GitPython doesn't check if this file\nis located outside the `.git` directory. This allows an attacker to make\nGitPython read any file from the system.\nCVE-2026-42215 From version 3.1.30 to before version 3.1.47, GitPython\nblocks dangerous Git options such as --upload-pack and --receive-pack by\ndefault, but the equivalent Python kwargs upload_pack and receive_pack\nbypass that check. If an application passes attacker-controlled kwargs\ninto Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(),\nthis leads to arbitrary command execution even when allow_unsafe_options\nis left at its default value of False. This issue has been patched in\nversion 3.1.47.\n","modified":"2026-09-03T18:15:04.080692168Z","published":"2026-09-03T18:06:14Z","upstream":["CVE-2023-40267","CVE-2023-41040","CVE-2026-42215"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0372.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35535"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AV5DV7GBLMOZT7U3Q4TDOJO5R6G3V6GH/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00036.html"},{"type":"ADVISORY","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.50"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.46"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.45"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.44"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.43"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.42"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.41"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.40"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.38"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.37"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.35"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.34"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.33"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.32"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.31"}],"affected":[{"package":{"name":"python-gitpython","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/python-gitpython?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.50-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0372.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}