UNKNOWNPyPI

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing 'git rev-list --output=<path>' to open and truncate the target file to zero bytes before revision parsing.

CVE-2026-73621Published 4 weeks agoUpdated 5 days agoSource: OSV

Affected packages

  • gitpythonbefore 3.1.56

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor | HackTribune