CVE-2026-73619: Gitpython Project Gitpython
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
Affected products
- Gitpython Project Gitpython: before 3.1.57 (fixed in 3.1.57)
Published 2026-08-13. Last modified 2026-09-03.