Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
CVE-2026-44243: GitPython library can let attackers execute code
CVE-2026-44243 · published 4 months ago
Summary
The GitPython code library used in several Linux packages can be tricked into running unwanted commands. This could let a malicious user take control of systems that rely on the library. Update to the latest released version of the GitPython package or the related python‑git packages to fix the problem.
What to do
- Update debian python-git to version 3.1.50-1.
- Update canonical python-git to version 0.3.2~RC1-3ubuntu0.1~esm3.
- Update canonical python-git to version 1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm4.
- Update canonical python-git to version 2.1.8-1ubuntu0.1~esm4.
- Update canonical python-git to version 3.0.7-1ubuntu0.1~esm4.
- Update canonical python-git to version 3.1.24-1ubuntu0.1~esm3.
- Update canonical python-git to version 3.1.37-3ubuntu0.1~esm2.
- Update canonical python-git to version 3.1.46-1ubuntu0.1~esm1.
- Update sebastian thiel, michael trier gitpython to version 3.1.48.
- Update sebastian thiel gitpython to version 3.1.48.
- Update rootio-gitpython to version 3.1.46+root.io.4.
- Update sebastian thiel gitpython to version 3.1.46+aikido.5.
- Update rootio-gitpython to version 3.1.46+root.io.5.
- Update sebastian thiel gitpython to version 3.1.47+aikido.1.
- Update rootio-gitpython to version 3.1.47+root.io.1.
- Update rootio-gitpython to version 3.1.47+root.io.2.
- Update rootio-gitpython to version 3.1.47+root.io.3.
- Update sebastian thiel gitpython to version 3.1.47+aikido.4.
- Update rootio-gitpython to version 3.1.46+root.io.6.
- Update sebastian thiel gitpython to version 3.1.46+aikido.8.
- Update sebastian thiel gitpython to version 3.1.46+aikido.9.
- Update sebastian thiel gitpython to version 3.1.46+aikido.10.
- Update gitpython to version 3.1.46+aikido.10.
- Update gitpython_project gitpython to version 3.1.48 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | python-git | All versions |
| Debian:13 | debian | python-git | All versions |
| Debian:14 | debian | python-git |
< 3.1.50-1 Fix: upgrade to 3.1.50-1
|
| Ubuntu:Pro:14.04:LTS | canonical | python-git |
< 0.3.2~RC1-3ubuntu0.1~esm3 Fix: upgrade to 0.3.2~RC1-3ubuntu0.1~esm3
|
| Ubuntu:Pro:16.04:LTS | canonical | python-git |
< 1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm4 Fix: upgrade to 1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm4
|
| Ubuntu:Pro:18.04:LTS | canonical | python-git |
< 2.1.8-1ubuntu0.1~esm4 Fix: upgrade to 2.1.8-1ubuntu0.1~esm4
|
| Ubuntu:Pro:20.04:LTS | canonical | python-git |
< 3.0.7-1ubuntu0.1~esm4 Fix: upgrade to 3.0.7-1ubuntu0.1~esm4
|
| Ubuntu:Pro:22.04:LTS | canonical | python-git |
< 3.1.24-1ubuntu0.1~esm3 Fix: upgrade to 3.1.24-1ubuntu0.1~esm3
|
| Ubuntu:Pro:24.04:LTS | canonical | python-git |
< 3.1.37-3ubuntu0.1~esm2 Fix: upgrade to 3.1.37-3ubuntu0.1~esm2
|
| Ubuntu:25.10 | canonical | python-git | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | python-git |
< 3.1.46-1ubuntu0.1~esm1 Fix: upgrade to 3.1.46-1ubuntu0.1~esm1
|
| PyPI | sebastian thiel, michael trier | gitpython |
< 3.1.48 Fix: upgrade to 3.1.48
|
| pip | sebastian thiel | gitpython |
<= 3.1.47 Fix: upgrade to 3.1.48
|
| – | gitpython_project | gitpython |
< 3.1.48 cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
| PyPI | sebastian thiel | gitpython |
< 3.1.48 Fix: upgrade to 3.1.48
|
| Root:PyPI | – | rootio-gitpython |
< 3.1.46+root.io.4 < 3.1.46+root.io.5 < 3.1.47+root.io.1 < 3.1.47+root.io.2 < 3.1.47+root.io.3 < 3.1.46+root.io.6 Fix: upgrade to 3.1.46+root.io.4
|
| Debian:11 | debian | python-git | All versions |
| Root:PyPI | sebastian thiel | gitpython |
< 3.1.46+aikido.5 < 3.1.47+aikido.1 < 3.1.47+aikido.4 < 3.1.46+aikido.8 < 3.1.46+aikido.9 < 3.1.46+aikido.10 Fix: upgrade to 3.1.46+aikido.5
|
| Root:PyPI | – | gitpython |
< 3.1.46+aikido.10 Fix: upgrade to 3.1.46+aikido.10
|
Original advisory text
CVE-2026-44243 in GitPython - Patched by Root
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.
References
- https://github.com/advisories/GHSA-7545-fcxq-7j24
- https://github.com/gitpython-developers/GitPython Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-44243 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-44243 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-44243 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8303-1 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-44243 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44243... Vendor Advisory
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48 Patch Release Notes
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7545-... Exploit Mitigation Vendor Advisory
Severity
7.8
High
CVSS 4.0: 7.8 (GHSA)
CVSS 3.1: 7.1 (OSV)
CVSS 4.0: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published7 May 2026
Updated29 Sep 2026
First seen6 May 2026
Sources
GHSA-7545-fcxq-7j24 · GHSA
CVE-2026-44243 · NVD
GHSA-7545-fcxq-7j24 · OSV
UBUNTU-CVE-2026-44243 · OSV
DEBIAN-CVE-2026-44243 · OSV
CVE-2026-44243 · OSV
Track software like this
Free during beta