Security Advisory

CVE-2026-73619

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 11:28:20
Last updated 2026-08-15 03:11:36
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.