What is CVE-2026-73623?
GitPython versions before 3.1.54 contain an incomplete denylist that omits the --template option, allowing arbitrary command execution during clone operations. This vulnerability primarily affects developers working with Git repositories, and immediate update to version 3.1.54 is strongly recommended.
Azərbaycanca: GitPython kitabxanasının 3.1.54 versiyasından əvvəlki versiyalarında qeyri-kafi bloklama siyahısı mövcuddur ki, bu da --template parametri vasitəsilə clone əməliyyatı zamanı ixtiyari əmr icrasına imkan verir. Bu boşluq xüsusilə Git repozitoriyaları ilə işləyən tərtibatçıları təsir edir və dərhal 3.1.54 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of the GitPython library are vulnerable to CVE-2026-73623?
All versions of the GitPython library before version 3.1.54 are vulnerable to this flaw.
During which Git operation can CVE-2026-73623 lead to arbitrary command execution?
This vulnerability can lead to arbitrary command execution during clone operations via the `--template` option.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.