What is CVE-2026-73621?
CVE-2026-73621 is an argument injection vulnerability in the Commit.count() method of GitPython before version 3.1.56, which forwards keyword arguments to 'git rev-list' without proper safety checks. An attacker controlling these options could execute arbitrary commands. Users should upgrade GitPython to version 3.1.56 or later immediately.
Azərbaycanca: CVE-2026-73621, GitPython kitabxanasının 3.1.56 versiyasından əvvəlki versiyalarında Commit.count() metodunda arqument inyeksiyası zəifliyidir. Bu, təhlükəsizlik yoxlaması olmadan `git rev-list` əmrinə ötürülən seçimləri idarə edə bilən hücumçuya ixtiyari əmrlər icra etməyə imkan verir. İstifadəçilər dərhal GitPython-u 3.1.56 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
In which library was CVE-2026-73621 discovered and which versions are affected?
CVE-2026-73621 was discovered in the GitPython library in versions prior to 3.1.56.
What should GitPython users do to protect against CVE-2026-73621?
Users should immediately upgrade GitPython to version 3.1.56 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.