What is CVE-2026-73625?
CVE-2026-73625 is a remote code execution (RCE) vulnerability in GitPython versions before 3.1.54, caused by a bypass in the `check_unsafe_options` guard via crafted single-character `kwargs` injected with git options. It affects functions like `clone_from` and `fetch`, and users must update to version 3.1.54 or later immediately.
Azərbaycanca: CVE-2026-73625, GitPython kitabxanasının 3.1.54-dən əvvəlki versiyalarında `check_unsafe_options` mühafizəsindən yan keçərək uzaqdan kod icrasına (RCE) səbəb olan boşluqdur. Bu boşluq `clone_from`, `fetch` kimi funksiyalara xüsusi hazırlanmış `kwargs` ötürməklə istismar edilə bilər. İstifadəçilər dərhal 3.1.54 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of GitPython are affected by CVE-2026-73625?
Versions before 3.1.54 are affected.
How to mitigate CVE-2026-73625?
Users must update to version 3.1.54 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.