CVE-2026-78679: Gitpython-Developers Gitpython
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.
Affected products
- Gitpython-Developers Gitpython: before 3.1.59 (fixed in 3.1.59)
Published 2026-08-25. Last modified 2026-09-24.