CVE-2026-78679: Gitpython-Developers Gitpython

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.

Affected products

Published 2026-08-25. Last modified 2026-09-24.