GitPython before 3.1.59 contains an arbitrary file read...
High severity
Unreviewed
Published
Aug 25, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 25, 2026
Published to the GitHub Advisory Database
Aug 25, 2026
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
References