GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)GHSA-3wxw-xv34-2frg
MEDIUMFix: gitpython-developers/GitPython#2208GHSA-3wxw-xv34-2frg is a medium-severity (CVSS 6.5) CWE-73 vulnerability in gitpython. A fix is available for gitpython — see the affected versions and patch details below.
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
Exploitation and automatability from CISA’s SSVC triage for GHSA-3wxw-xv34-2frg.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-3wxw-xv34-2frg by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 384,534 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
gitpythonReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Summary
TagReference.create() forwards a caller-influenced positional reference value into git tag without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit 3af0c251 (the fix for GHSA-3f7w-8rr8-f37f's tag instance).
Root Cause
The fix 3af0c251 added unsafe_git_tag_options = ["--file","-F"] and a guard call, but the guard is Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...) at git/refs/tag.py:139 — it passes an EMPTY args list and inspects kwargs only. The dangerous values path and reference are POSITIONALS (args = (path, reference), tag.py:156), placed before any --. A user-influenced reference="--file=<path>" therefore reaches git tag as the exact --file option the fix intended to block, creating an annotated tag whose message is the file's contents.
Impact
Arbitrary local file read at the privileges of the host process; contents returned in-band via tagref.tag.message. Requires the embedding application to forward a caller-influenced reference value into TagReference.create() (pure VALUE control — the CVE-2026-42215 threat model). Default allow_unsafe_options=False.
Proof of Concept
from git import TagReference
t = TagReference.create(repo, "vpwn", reference="--file=/home/app/.ssh/id_rsa")
print(t.tag.message) # contents of the file
Attack Chain
- Entry: app calls
TagReference.create(repo, name, reference=<user>)withreference="--file=/home/app/.ssh/id_rsa". - Check:
Git.check_unsafe_options(_option_candidates([], kwargs), ["--file","-F"])@ tag.py:137-141. Guard: denylist includes--file/-F. Bypass proof:_option_candidatesreceivesargs=[]→ the positionalreferenceis never a candidate (the kwarg spellingfile="…"IS blocked; only the positional escapes). - Sink:
repo.git.tag(*args, **kwargs)@ tag.py:158 → no--. argv (observed):['git','tag','-f','vpwn','--file=<secret>']. - Impact: annotated tag created;
tagref.tag.message== file contents (arbitrary file read).
Bypass Evidence
Independently reproduced (independent test harness, git 2.43.0, default allow_unsafe_options=False): TagReference.create(repo,'vp','--file=<secret>') → PASSED; tag.message == 'GATE_SECRET_LINE_A\nGATE_SECRET_LINE_B'. Control: TagReference.create(..., file='<secret>') → UnsafeOptionError: --file is not allowed. Fix-commit read: 3af0c251 adds _option_candidates([], kwargs) (empty args → positional never a candidate).
Affected Versions
GitPython <= 3.1.58 (sink present verbatim on the latest release tag; git diff 3.1.57..HEAD touches only test files).
Suggested Fix
Include the positional reference (and path) in the option-candidate list passed to check_unsafe_options, or place a -- separator before the positional arguments in TagReference.create().
Reported by zx (Jace) — GitHub: @manus-use
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | gitpython | all versions | 3.1.59pip install --upgrade 'gitpython==3.1.59' |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for gitpython, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update gitpython to 3.1.59 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-3wxw-xv34-2frg is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
A flaw was found in GitPython's TagReference.create() function. An incomplete fix for a prior vulnerability (GHSA-3f7w-8rr8-f37f) failed to validate positional parameters, allowing an attacker with low privileges to supply a specially crafted reference value (such as --file=/path/to/file) to read arbitrary files on…
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.Source: Red Hat security advisory for GHSA-3wxw-xv34-2frg (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Ansible Automation Platform 2.5 for RHEL 8 | python3.12-gitpython-0:3.1.59-1.el8ap | RHSA-2026:59135 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | python3.12-gitpython-0:3.1.59-1.el9ap | RHSA-2026:59136 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | automation-controller-0:4.7.17-1.el9ap | RHSA-2026:71113 |
| Red Hat Satellite 6.16 for RHEL 8 | python-gitpython-0:3.1.62-1.el8pc | RHSA-2026:74506 |
| Red Hat Satellite 6.17 for RHEL 9 | python-gitpython-0:3.1.62-1.el9pc | RHSA-2026:74505 |
| Red Hat Satellite 6.18 for RHEL 9 | python3.12-gitpython-0:3.1.62-1.el9pc | RHSA-2026:74504 |
| Red Hat Satellite 6.19 for RHEL 9 | python3.12-gitpython-0:3.1.62-1.el9pc | RHSA-2026:74503 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/controller-rhel9:1789673739 | RHSA-2026:71179 |
Frequently Asked Questions
Is GHSA-3wxw-xv34-2frg in your dependencies?
Find it across PyPI, including transitive dependencies.