Skip to main content
HIGH

CVE-2026-67323

CVSS v3

8.4

HIGH

EPSS Score

1.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-contro

Technical details

CVSS v3 Vector
3.1
Published
2026-08-01
Last Modified
2026-08-01

Frequently asked questions

What is CVE-2026-67323?

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-contro

Is CVE-2026-67323 actively exploited?

Active exploitation of CVE-2026-67323 has not been confirmed. The EPSS score is 1.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-67323?

CVE-2026-67323 has a CVSS v3 base score of 8.4 (HIGH severity), with vector string 3.1.

Is CVE-2026-67323 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key