CVE-2026-78679 - GitPython before 3.1.59 Arbitrary File Read via TagReference.create
CVE ID :CVE-2026-78679
Published : Aug. 25, 2026, 2:16 a.m. | 2 hours, 12 minutes ago
Description :GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 25, 2026, 2:16 a.m. | 2 hours, 12 minutes ago
Description :GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...