Vulnerability Description
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-
- https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-v
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-
FAQ
What is CVE-2026-73624?
CVE-2026-73624 is a vulnerability with a CVSS score of 8.1 (HIGH). GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --outp...
How severe is CVE-2026-73624?
CVE-2026-73624 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73624?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.