[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:4072-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":68,"duplicates":69,"related":70,"reserved_at":9,"published_at":98,"modified_at":99,"state":9,"summary":100,"references_raw":102,"kevs":331,"epss":9,"epss_history":332,"metrics":333,"affected":334},"SUSE-SU-2026:4072-1","Security update for python-GitPython\n\nThis update for python-GitPython fixes the following issues:\n\n- CVE-2026-42215: command injection via Git options bypass (bsc#1264604).\n- CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605).\n- CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the\n  repository (bsc#1264606).\n- CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608).\n- CVE-2026-67322: vulnerable to environment-variable exfiltration in Repo.clone_from() (bsc#1273357).\n- CVE-2026-67323: fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and\n  git.ls_remote() (bsc#1273358).\n- CVE-2026-67325: contains an incomplete command injection blocklist that fails to account for git's long-option prefix\n  abbreviation feature (bsc#1273359).\n- CVE-2026-67326: fails to validate newline characters in the section parameter of config_writer() (bsc#1273364).\n- CVE-2026-69097: fails to properly escape section names in git config files, allowing attackers to inject arbitrary\n  configuration directives through malicious submodule names (bsc#1273414).\n- CVE-2026-73619: incomplete denylist in the `unsafe_git_archive_options` guard that omits `--add-file` and `--add-\n  virtual-file` options can lead to arbitrary file reads (bsc#1275755).\n- CVE-2026-73620: failure to guard git option forwarding in `IndexFile.checkout()` and `TagReference.create()` can lead\n  to arbitrary file reads and writes (bsc#1275756).\n- CVE-2026-73621: argument injection in the `Commit.count()` method allows for destruction/blanking of arbitrary files\n  (bsc#1275757).\n- CVE-2026-73622: failure to disable environment variable expansion in `Remote.create()` and `Submodule.add()` URL\n  handling allows for secret exfiltration via URLs containing variable references (bsc#1275751).\n- CVE-2026-73623: incomplete denylist in `unsafe_git_clone_options` that omits `--template` allows for arbitrary command\n  execution (bsc#1275752).\n- CVE-2026-73624: `Diffable.diff` method fails to validate git options passed through `kwargs`, which can lead to\n  arbitrary file writes (bsc#1275753).\n- CVE-2026-73625: `check_unsafe_options` guard bypass via smuggling of git options inside single-character `kwarg`\n  values can lead to arbitrary code execution (bsc#1275754).\n- CVE-2026-76217: failure to validate options passed to `git rm` and `git checkout` commands in `IndexFile.remove()` and\n  `Head.checkout()` can lead to arbitrary file reads (bsc#1275745).\n- CVE-2026-76218: unguarded git option forwarding in `Repo.init` allows for arbitrary command execution (bsc#1275746).\n- CVE-2026-76219: unguarded `git read-tree` option forwarding in `IndexFile.from_tree/reset/merge_tree` can lead to\n  arbitrary file overwrites (bsc#1275747).\n- CVE-2026-76220: `check_unsafe_options` guard can be bypassed by combining a single-character `kwarg` with\n  `split_single_char_options=False`, which can lead to arbitrary OS command injection (bsc#1275748).\n- CVE-2026-76221: `config-name` injection in the `option-name` validator can lead to remote code execution\n  (bsc#1275749).\n- CVE-2026-76222: failure to validate submodule names from `.gitmodules` files allows creation of Git repositories at\n  arbitrary filesystem paths outside the intended clone directory (bsc#1275750).\n- CVE-2026-78675: fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file\n  content by including arbitrary file paths via [include] directives (bsc#1276434).\n- CVE-2026-78676: fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant\n  quoted values into injected directives (bsc#1276433).\n- CVE-2026-78677: allowing creation of arbitrary git directories outside the intended clone destination (bsc#1276432).\n- CVE-2026-78678: an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options,\n  allowing attackers to read arbitrary files (bsc#1276431).\n- CVE-2026-78679: an arbitrary file read vulnerability in TagReference.create() (bsc#1276430).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66],{"_key":15},"CVE-2026-42215",{"_key":17},"CVE-2026-42284",{"_key":19},"CVE-2026-44243",{"_key":21},"CVE-2026-44244",{"_key":23},"CVE-2026-67322",{"_key":25},"CVE-2026-67323",{"_key":27},"CVE-2026-67325",{"_key":29},"CVE-2026-67326",{"_key":31},"CVE-2026-69097",{"_key":33},"CVE-2026-73619",{"_key":35},"CVE-2026-73620",{"_key":37},"CVE-2026-73621",{"_key":39},"CVE-2026-73622",{"_key":41},"CVE-2026-73623",{"_key":43},"CVE-2026-73624",{"_key":45},"CVE-2026-73625",{"_key":47},"CVE-2026-76217",{"_key":49},"CVE-2026-76218",{"_key":51},"CVE-2026-76219",{"_key":53},"CVE-2026-76220",{"_key":55},"CVE-2026-76221",{"_key":57},"CVE-2026-76222",{"_key":59},"CVE-2026-78675",{"_key":61},"CVE-2026-78676",{"_key":63},"CVE-2026-78677",{"_key":65},"CVE-2026-78678",{"_key":67},"CVE-2026-78679",[],[],[71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},"2026-09-08T07:07:35Z","2026-09-13T18:23:19.859020490Z",{"cisa_kev":101,"cisa_ransomware":101,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[103,109,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,210,214,218,222,227,231,235,239,243,247,251,255,259,263,267,271,275,279,283,287,291,295,299,303,307,311,315,319,323,327],{"url":104,"sources":105,"tags":107},"https://www.suse.com/support/update/announcement/2026/suse-su-20264072-1/",[106],"osv_suse",[108],"Advisory",{"url":110,"sources":111,"tags":112},"https://bugzilla.suse.com/1264604",[106],[113],"REPORT",{"url":115,"sources":116,"tags":117},"https://bugzilla.suse.com/1264605",[106],[113],{"url":119,"sources":120,"tags":121},"https://bugzilla.suse.com/1264606",[106],[113],{"url":123,"sources":124,"tags":125},"https://bugzilla.suse.com/1264608",[106],[113],{"url":127,"sources":128,"tags":129},"https://bugzilla.suse.com/1273357",[106],[113],{"url":131,"sources":132,"tags":133},"https://bugzilla.suse.com/1273358",[106],[113],{"url":135,"sources":136,"tags":137},"https://bugzilla.suse.com/1273359",[106],[113],{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1273364",[106],[113],{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1273414",[106],[113],{"url":147,"sources":148,"tags":149},"https://bugzilla.suse.com/1273498",[106],[113],{"url":151,"sources":152,"tags":153},"https://bugzilla.suse.com/1275745",[106],[113],{"url":155,"sources":156,"tags":157},"https://bugzilla.suse.com/1275746",[106],[113],{"url":159,"sources":160,"tags":161},"https://bugzilla.suse.com/1275747",[106],[113],{"url":163,"sources":164,"tags":165},"https://bugzilla.suse.com/1275748",[106],[113],{"url":167,"sources":168,"tags":169},"https://bugzilla.suse.com/1275749",[106],[113],{"url":171,"sources":172,"tags":173},"https://bugzilla.suse.com/1275750",[106],[113],{"url":175,"sources":176,"tags":177},"https://bugzilla.suse.com/1275751",[106],[113],{"url":179,"sources":180,"tags":181},"https://bugzilla.suse.com/1275752",[106],[113],{"url":183,"sources":184,"tags":185},"https://bugzilla.suse.com/1275753",[106],[113],{"url":187,"sources":188,"tags":189},"https://bugzilla.suse.com/1275754",[106],[113],{"url":191,"sources":192,"tags":193},"https://bugzilla.suse.com/1275755",[106],[113],{"url":195,"sources":196,"tags":197},"https://bugzilla.suse.com/1275756",[106],[113],{"url":199,"sources":200,"tags":201},"https://bugzilla.suse.com/1275757",[106],[113],{"url":203,"sources":204,"tags":205},"https://bugzilla.suse.com/1276430",[106],[113],{"url":207,"sources":208,"tags":209},"https://bugzilla.suse.com/1276431",[106],[113],{"url":211,"sources":212,"tags":213},"https://bugzilla.suse.com/1276432",[106],[113],{"url":215,"sources":216,"tags":217},"https://bugzilla.suse.com/1276433",[106],[113],{"url":219,"sources":220,"tags":221},"https://bugzilla.suse.com/1276434",[106],[113],{"url":223,"sources":224,"tags":225},"https://www.suse.com/security/cve/CVE-2026-42215",[106],[226],"WEB",{"url":228,"sources":229,"tags":230},"https://www.suse.com/security/cve/CVE-2026-42284",[106],[226],{"url":232,"sources":233,"tags":234},"https://www.suse.com/security/cve/CVE-2026-44243",[106],[226],{"url":236,"sources":237,"tags":238},"https://www.suse.com/security/cve/CVE-2026-44244",[106],[226],{"url":240,"sources":241,"tags":242},"https://www.suse.com/security/cve/CVE-2026-67322",[106],[226],{"url":244,"sources":245,"tags":246},"https://www.suse.com/security/cve/CVE-2026-67323",[106],[226],{"url":248,"sources":249,"tags":250},"https://www.suse.com/security/cve/CVE-2026-67325",[106],[226],{"url":252,"sources":253,"tags":254},"https://www.suse.com/security/cve/CVE-2026-67326",[106],[226],{"url":256,"sources":257,"tags":258},"https://www.suse.com/security/cve/CVE-2026-69097",[106],[226],{"url":260,"sources":261,"tags":262},"https://www.suse.com/security/cve/CVE-2026-73619",[106],[226],{"url":264,"sources":265,"tags":266},"https://www.suse.com/security/cve/CVE-2026-73620",[106],[226],{"url":268,"sources":269,"tags":270},"https://www.suse.com/security/cve/CVE-2026-73621",[106],[226],{"url":272,"sources":273,"tags":274},"https://www.suse.com/security/cve/CVE-2026-73622",[106],[226],{"url":276,"sources":277,"tags":278},"https://www.suse.com/security/cve/CVE-2026-73623",[106],[226],{"url":280,"sources":281,"tags":282},"https://www.suse.com/security/cve/CVE-2026-73624",[106],[226],{"url":284,"sources":285,"tags":286},"https://www.suse.com/security/cve/CVE-2026-73625",[106],[226],{"url":288,"sources":289,"tags":290},"https://www.suse.com/security/cve/CVE-2026-76217",[106],[226],{"url":292,"sources":293,"tags":294},"https://www.suse.com/security/cve/CVE-2026-76218",[106],[226],{"url":296,"sources":297,"tags":298},"https://www.suse.com/security/cve/CVE-2026-76219",[106],[226],{"url":300,"sources":301,"tags":302},"https://www.suse.com/security/cve/CVE-2026-76220",[106],[226],{"url":304,"sources":305,"tags":306},"https://www.suse.com/security/cve/CVE-2026-76221",[106],[226],{"url":308,"sources":309,"tags":310},"https://www.suse.com/security/cve/CVE-2026-76222",[106],[226],{"url":312,"sources":313,"tags":314},"https://www.suse.com/security/cve/CVE-2026-78675",[106],[226],{"url":316,"sources":317,"tags":318},"https://www.suse.com/security/cve/CVE-2026-78676",[106],[226],{"url":320,"sources":321,"tags":322},"https://www.suse.com/security/cve/CVE-2026-78677",[106],[226],{"url":324,"sources":325,"tags":326},"https://www.suse.com/security/cve/CVE-2026-78678",[106],[226],{"url":328,"sources":329,"tags":330},"https://www.suse.com/security/cve/CVE-2026-78679",[106],[226],[],[],[],[335,348,352,356,360,364,368,372,376,380,384],{"ecosystem":336,"name":337,"vendor":338,"product":339,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":339,"source":9,"versions":341},"SUSE Linux Enterprise","python-GitPython","suse","python-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS","rpm",[342],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},"lt3_1_34_1693646983_2a2ae77_150400_9_8_1",true,"ecosystem","3.1.34.1693646983.2a2ae77-150400.9.8.1","excluding",{"ecosystem":336,"name":337,"vendor":338,"product":349,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":349,"source":9,"versions":350},"python-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",[351],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":353,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":353,"source":9,"versions":354},"python-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",[355],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":357,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":357,"source":9,"versions":358},"python-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",[359],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":361,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":361,"source":9,"versions":362},"python-GitPython&distro=SUSE Linux Enterprise Module for Python 3 15 SP7",[363],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":365,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":365,"source":9,"versions":366},"python-GitPython&distro=SUSE Linux Enterprise Server 15 SP4-LTSS",[367],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":369,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":369,"source":9,"versions":370},"python-GitPython&distro=SUSE Linux Enterprise Server 15 SP5-LTSS",[371],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":373,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":373,"source":9,"versions":374},"python-GitPython&distro=SUSE Linux Enterprise Server 15 SP6-LTSS",[375],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":377,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":377,"source":9,"versions":378},"python-GitPython&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4",[379],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":381,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":381,"source":9,"versions":382},"python-GitPython&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP5",[383],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9},{"ecosystem":336,"name":337,"vendor":338,"product":385,"cpe_part":9,"purl_type":340,"purl_namespace":338,"purl_name":385,"source":9,"versions":386},"python-GitPython&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6",[387],{"version":343,"is_range":344,"range_type":345,"version_start":9,"version_start_type":9,"version_end":346,"version_end_type":347,"fixed_in":9}]