Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-44243: GitPython library can let attackers execute code

CVE-2026-44243 · published 4 months ago
Summary

The GitPython code library used in several Linux packages can be tricked into running unwanted commands. This could let a malicious user take control of systems that rely on the library. Update to the latest released version of the GitPython package or the related python‑git packages to fix the problem.

What to do
  • Update debian python-git to version 3.1.50-1.
  • Update canonical python-git to version 0.3.2~RC1-3ubuntu0.1~esm3.
  • Update canonical python-git to version 1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm4.
  • Update canonical python-git to version 2.1.8-1ubuntu0.1~esm4.
  • Update canonical python-git to version 3.0.7-1ubuntu0.1~esm4.
  • Update canonical python-git to version 3.1.24-1ubuntu0.1~esm3.
  • Update canonical python-git to version 3.1.37-3ubuntu0.1~esm2.
  • Update canonical python-git to version 3.1.46-1ubuntu0.1~esm1.
  • Update sebastian thiel, michael trier gitpython to version 3.1.48.
  • Update sebastian thiel gitpython to version 3.1.48.
  • Update rootio-gitpython to version 3.1.46+root.io.4.
  • Update sebastian thiel gitpython to version 3.1.46+aikido.5.
  • Update rootio-gitpython to version 3.1.46+root.io.5.
  • Update sebastian thiel gitpython to version 3.1.47+aikido.1.
  • Update rootio-gitpython to version 3.1.47+root.io.1.
  • Update rootio-gitpython to version 3.1.47+root.io.2.
  • Update rootio-gitpython to version 3.1.47+root.io.3.
  • Update sebastian thiel gitpython to version 3.1.47+aikido.4.
  • Update rootio-gitpython to version 3.1.46+root.io.6.
  • Update sebastian thiel gitpython to version 3.1.46+aikido.8.
  • Update sebastian thiel gitpython to version 3.1.46+aikido.9.
  • Update sebastian thiel gitpython to version 3.1.46+aikido.10.
  • Update gitpython to version 3.1.46+aikido.10.
  • Update gitpython_project gitpython to version 3.1.48 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian python-git All versions
Debian:13 debian python-git All versions
Debian:14 debian python-git < 3.1.50-1
Fix: upgrade to 3.1.50-1
Ubuntu:Pro:14.04:LTS canonical python-git < 0.3.2~RC1-3ubuntu0.1~esm3
Fix: upgrade to 0.3.2~RC1-3ubuntu0.1~esm3
Ubuntu:Pro:16.04:LTS canonical python-git < 1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm4
Fix: upgrade to 1.0.1+git137-gc8b8379-2.1ubuntu0.1~esm4
Ubuntu:Pro:18.04:LTS canonical python-git < 2.1.8-1ubuntu0.1~esm4
Fix: upgrade to 2.1.8-1ubuntu0.1~esm4
Ubuntu:Pro:20.04:LTS canonical python-git < 3.0.7-1ubuntu0.1~esm4
Fix: upgrade to 3.0.7-1ubuntu0.1~esm4
Ubuntu:Pro:22.04:LTS canonical python-git < 3.1.24-1ubuntu0.1~esm3
Fix: upgrade to 3.1.24-1ubuntu0.1~esm3
Ubuntu:Pro:24.04:LTS canonical python-git < 3.1.37-3ubuntu0.1~esm2
Fix: upgrade to 3.1.37-3ubuntu0.1~esm2
Ubuntu:25.10 canonical python-git All versions
Ubuntu:Pro:26.04:LTS canonical python-git < 3.1.46-1ubuntu0.1~esm1
Fix: upgrade to 3.1.46-1ubuntu0.1~esm1
PyPI sebastian thiel, michael trier gitpython < 3.1.48
Fix: upgrade to 3.1.48
pip sebastian thiel gitpython <= 3.1.47
Fix: upgrade to 3.1.48
– gitpython_project gitpython < 3.1.48
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
PyPI sebastian thiel gitpython < 3.1.48
Fix: upgrade to 3.1.48
Root:PyPI – rootio-gitpython < 3.1.46+root.io.4
< 3.1.46+root.io.5
< 3.1.47+root.io.1
< 3.1.47+root.io.2
< 3.1.47+root.io.3
< 3.1.46+root.io.6
Fix: upgrade to 3.1.46+root.io.4
Debian:11 debian python-git All versions
Root:PyPI sebastian thiel gitpython < 3.1.46+aikido.5
< 3.1.47+aikido.1
< 3.1.47+aikido.4
< 3.1.46+aikido.8
< 3.1.46+aikido.9
< 3.1.46+aikido.10
Fix: upgrade to 3.1.46+aikido.5
Root:PyPI – gitpython < 3.1.46+aikido.10
Fix: upgrade to 3.1.46+aikido.10
Original advisory text
CVE-2026-44243 in GitPython - Patched by Root
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.
Severity
7.8 High
CVSS 4.0: 7.8 (GHSA)
CVSS 3.1: 7.1 (OSV)
CVSS 4.0: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published7 May 2026
Updated29 Sep 2026
First seen6 May 2026
Track software like this
Free during beta