CRITICALPyPI

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

CVE-2026-67325Published 2 weeks agoUpdated 3 days agoSource: OSV

Affected packages

  • gitpythonbefore 3.1.51

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
1.48%
EPSS percentile
71.4%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 71%.

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist | HackTribune