CVE-2023-40267: Gitpython Project Gitpython
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
Affected products
- Gitpython Project Gitpython: before 3.1.32 (fixed in 3.1.32)
Published 2023-08-11. Last modified 2026-06-17.