GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.
CVSS Details
- CVSS 4.0 Base Score: 7.1 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3.12-django-ansible-base+jwt_consumerUpgrade aap-metrics-utilityUpgrade python3.12-sqlparseUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-controller-venv-towerUpgrade automation-gateway-proxy-serverUpgrade automation-gateway-proxy-server-debuginfoUpgrade automation-platform-uiUpgrade python3.12-django-ansible-base+activitystreamUpgrade python3.12-galaxy-ngUpgrade automation-gateway-serverUpgrade automation-controller-serverUpgrade receptorctlUpgrade automation-gatewayUpgrade automation-controller-cliUpgrade automation-controllerUpgrade receptor-debugsourceUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-gateway-proxy-debugsourceUpgrade receptor-debuginfoUpgrade automation-eda-controller-base-servicesUpgrade python3.12-gitpythonUpgrade python3.12-django-ansible-base+feature_flagsUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3-sqlparseUpgrade python3.12-django-ansible-base+authenticationUpgrade automation-gateway-configUpgrade python3.12-django-ansible-baseUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-eda-controller-baseUpgrade automation-eda-controllerUpgrade python3.12-django-ansible-base+rbacUpgrade receptorUpgrade python3.12-django-ansible-base+channel_authUpgrade automation-hubUpgrade automation-gateway-proxyUpgrade automation-eda-controller-worker-servicesUpgrade automation-controller-uiUpgrade python3.12-django-ansible-base+api_documentation | Sep 25, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub