CVE-2026-87818
Awaiting Analysis Awaiting Analysis - Queue

GitPython diff API Arbitrary File Read via --no-index

Vulnerability report for CVE-2026-87818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gitpython_developers gitpython From 3.1.59 (inc) to 3.1.60 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GitPython 3.1.59 fails to restrict the --no-index option in its high-level diff API, allowing attackers to read arbitrary filesystem paths. By combining --no-index with -I/--ignore-matching-lines, attackers can create a content-dependent Boolean oracle. This oracle uses distinguishable success or error responses to recover single-line secrets from local files through repeated API queries.

Detection Guidance

To detect this vulnerability, check if your system uses GitPython version 3.1.59 or vulnerable versions below 3.1.60. Review applications that expose GitPython's diff API with attacker-controlled options and paths. Test for the presence of unsafe --no-index usage combined with -I/--ignore-matching-lines in diff commands.

Impact Analysis

This vulnerability allows attackers to read local files accessible by the GitPython process if an application exposes the diff API with attacker-controlled options and paths. It can lead to disclosure of sensitive information like secrets, configuration files, or other local data. The attack is particularly effective against short or structured single-line secrets.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive personal or health information, violating GDPR and HIPAA compliance. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A breach via this flaw may result in regulatory penalties, legal liabilities, and reputational damage.

Mitigation Strategies

Immediately upgrade GitPython to version 3.1.60 or later. If upgrading is not possible, ensure allow_unsafe_options is set to False and block --no-index usage in high-level diff APIs. Audit applications using GitPython for exposed diff interfaces and restrict user control over diff options and paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87818. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart