CVE-2026-73625 | gitpython-developers GitPython up to 3.1.53 check_unsafe_options upload-pack os command injection

SecurityVulns

A vulnerability marked as critical has been reported in gitpython-developers GitPython up to 3.1.53. This issue affects the function clone_from/fetch/pull/push/ls_remote/iter_commits/blame/archive of the component check_unsafe_options. The manipulation of the argument upload-pack leads to os command injection.

This vulnerability is listed as CVE-2026-73625. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More