Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-67325: GitPython library can let attackers execute code

CVE-2026-67325 · published 5 days ago
Summary

The GitPython code library used in several Linux packages can be tricked into running unauthorized programs. This could let a malicious user gain control of the system where the library is installed. Update to the latest released version of GitPython from your package source to protect your environment.

What to do
  • Update gitpython to version 3.1.51.
  • Update sebastian thiel gitpython to version 3.1.51.
  • Update debian python-git to version 3.1.61-1.
  • Update gitpython to version 3.1.46+aikido.13.
  • Update gitpython to version 3.1.46+aikido.11.
  • Update gitpython to version 3.1.47+aikido.3.
  • Update gitpython-developers gitpython to version 3.1.51 or later.
  • Update gitpython_project gitpython to version 3.1.51 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian python-git All versions
Debian:12 debian python-git All versions
Debian:13 debian python-git All versions
Debian:14 debian python-git < 3.1.61-1
Fix: upgrade to 3.1.61-1
Ubuntu:Pro:14.04:LTS canonical python-git All versions
Ubuntu:Pro:16.04:LTS canonical python-git All versions
Ubuntu:Pro:18.04:LTS canonical python-git All versions
Ubuntu:Pro:20.04:LTS canonical python-git All versions
Ubuntu:Pro:22.04:LTS canonical python-git All versions
Ubuntu:Pro:24.04:LTS canonical python-git All versions
Ubuntu:Pro:26.04:LTS canonical python-git All versions
– gitpython-developers gitpython < 3.1.51
pip – gitpython <= 3.1.50
Fix: upgrade to 3.1.51
pip sebastian thiel gitpython <= 3.1.50
Fix: upgrade to 3.1.51
– gitpython_project gitpython < 3.1.51
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
Root:PyPI – gitpython < 3.1.46+aikido.13
< 3.1.46+aikido.11
Fix: upgrade to 3.1.46+aikido.13
PyPI – gitpython < 3.1.51
Fix: upgrade to 3.1.51
Root:PyPI – gitpython < 3.1.47+aikido.3
Fix: upgrade to 3.1.47+aikido.3
Original advisory text
CVE-2026-67325 in gitpython - Patched by Root
Root has patched CVE-2026-67325 in the gitpython package for Root:PyPI. Multiple fixed versions available.
Severity
8.7 High
CVSS 3.1: 8.8 (GHSA)
CVSS 3.1: 8.8 (MITRE)
CVSS 4.0: 9.4 (OSV)
CVSS 3.1: 8.8 (OSV)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
CWE-184Incomplete List of Disallowed Inputs
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen21 Jul 2026
Track software like this
Free during beta