NVD HIGH: CVE-2026-67323 — GitPython before 3.1.51 fails to guard against dangerous Git options passed as k...
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to o
CVE-2026-67323