Target: gitpython-developers/GitPython
Tested: HEAD 07e80555 (2026-07-25), latest release 3.1.55, git version 2.50.1
Reported instances: 2 exploitable, from a sweep of 14 unguarded call sites
Summary
GitPython blocks dangerous git options through Git.check_unsafe_options(), gated per method by an allow_unsafe_options parameter. That guard is applied per call site, so any API that forwards **kwargs into a git command without calling it passes caller-controlled options straight to git.
A mechanical sweep of every method that forwards **kwargs into a .git.<command>(...) call found 14 sites with no guard. Two reach a git option that takes a filesystem path:
| # | Call site | git option | Impact |
|---|---|---|---|
| 1 | IndexFile.checkout() → git checkout-index | --prefix=<path> | arbitrary file overwrite with repository-controlled content |
| 2 | TagReference.create() → git tag | -F <file> / --file=<file> | arbitrary file read, returned in-band |
This is the same defect class already fixed in Commit.count() (GHSA-p538-c434-8v24), Repo.archive() and Git.ls_remote() (GHSA-956x-8gvw-wg5v). Both instances below are still present at HEAD.
Instance 1 — IndexFile.checkout(): arbitrary file overwrite
git/index/base.py:1210 accepts **kwargs and forwards them with no guard:
def checkout(self, paths=None, force=False, fprogress=lambda *args: None, **kwargs):
...
proc = self.repo.git.checkout_index(*args, **kwargs) # line 1331
...
proc = self.repo.git.checkout_index(args, **kwargs) # line 1349