[Git][security-tracker-team/security-tracker][master] CVE-2026-78679: Add commit link

Emmanuel Arias (@eamanu) eamanu at debian.org
Fri Sep 18 21:46:46 BST 2026



Emmanuel Arias pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7d8bcaac by Emmanuel Arias at 2026-09-18T17:46:31-03:00
CVE-2026-78679: Add commit link

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -33541,6 +33541,7 @@ CVE-2026-78680 (NLTK versions before 3.10.3 fail to use validated absolute paths
 CVE-2026-78679 (GitPython before 3.1.59 contains an arbitrary file read vulnerability  ...)
 	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg
+	NOTE: Fixed by: https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6 (3.1.59)
 CVE-2026-78678 (GitPython versions before 3.1.59 contain an incomplete denylist in the ...)
 	- python-git 3.1.61-1 (bug #1145672)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d8bcaacb39e533a9247cb2159d794c8cb3c52f1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7d8bcaacb39e533a9247cb2159d794c8cb3c52f1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/78363e98/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list