Disclosure summary
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-whh4-5q6c-9v3x. This link is maintained to preserve external references. ## Original Description GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-rw58-wc66-99g4
Open original source · Updated Sep 30, 2026
Withdrawn advisoryDuplicate Advisory: GitPython 3.1.59: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
Source severity: HIGH / 7.1
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | gitpython | >= 3.1.59, < 3.1.60 | Not supplied |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-09T08:32:15-04:00
MODIFIED 2026-09-30T19:28:16-04:00
INGESTED 2026-10-06T11:45:02-04:00