GHSA-6rj2-96f5-chj9HighCVSS 6.5
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create()...
🔗 CVE IDs covered (1)
📋 Description
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.