Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-67325: GitPython library can let attackers execute code
CVE-2026-67325 · published 5 days ago
Summary
The GitPython code library used in several Linux packages can be tricked into running unauthorized programs. This could let a malicious user gain control of the system where the library is installed. Update to the latest released version of GitPython from your package source to protect your environment.
What to do
- Update gitpython to version 3.1.51.
- Update sebastian thiel gitpython to version 3.1.51.
- Update debian python-git to version 3.1.61-1.
- Update gitpython to version 3.1.46+aikido.13.
- Update gitpython to version 3.1.46+aikido.11.
- Update gitpython to version 3.1.47+aikido.3.
- Update gitpython-developers gitpython to version 3.1.51 or later.
- Update gitpython_project gitpython to version 3.1.51 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | python-git | All versions |
| Debian:12 | debian | python-git | All versions |
| Debian:13 | debian | python-git | All versions |
| Debian:14 | debian | python-git |
< 3.1.61-1 Fix: upgrade to 3.1.61-1
|
| Ubuntu:Pro:14.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | python-git | All versions |
| – | gitpython-developers | gitpython | < 3.1.51 |
| pip | – | gitpython |
<= 3.1.50 Fix: upgrade to 3.1.51
|
| pip | sebastian thiel | gitpython |
<= 3.1.50 Fix: upgrade to 3.1.51
|
| – | gitpython_project | gitpython |
< 3.1.51 cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
| Root:PyPI | – | gitpython |
< 3.1.46+aikido.13 < 3.1.46+aikido.11 Fix: upgrade to 3.1.46+aikido.13
|
| PyPI | – | gitpython |
< 3.1.51 Fix: upgrade to 3.1.51
|
| Root:PyPI | – | gitpython |
< 3.1.47+aikido.3 Fix: upgrade to 3.1.47+aikido.3
|
Original advisory text
CVE-2026-67325 in gitpython - Patched by Root
Root has patched CVE-2026-67325 in the gitpython package for Root:PyPI. Multiple fixed versions available.
References
- https://security-tracker.debian.org/tracker/CVE-2026-67325 Vendor Advisory
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-...
- https://github.com/gitpython-developers/GitPython/pull/2161
- https://github.com/gitpython-developers/GitPython/commit/56806080c1348749b07daa4...
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51
- https://github.com/advisories/GHSA-2f96-g7mh-g2hx
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67325... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-67325
- https://www.cve.org/CVERecord?id=CVE-2026-67325 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-67325 Third Party Advisory
- https://github.com/gitpython-developers/GitPython Product
- https://pypi.org/project/gitpython Product
- https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-opti...
Severity
8.7
High
CVSS 3.1: 8.8 (GHSA)
CVSS 3.1: 8.8 (MITRE)
CVSS 4.0: 9.4 (OSV)
CVSS 3.1: 8.8 (OSV)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
CWE-184Incomplete List of Disallowed Inputs
Timeline
Published22 Sep 2026
Updated25 Sep 2026
First seen21 Jul 2026
Sources
CVE-2026-67325 · NVD
UBUNTU-CVE-2026-67325 · OSV
DEBIAN-CVE-2026-67325 · OSV
CVE-2026-67325 · MITRE
GHSA-2f96-g7mh-g2hx · GHSA
CVE-2026-67325 · OSV
PYSEC-2026-3836 · OSV
Track software like this
Free during beta