/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-22190

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-22190

Severity

7.8

High

CVSS V3

Summary

Untrusted search path under some conditions on Windows allows arbitrary code execution

Description

GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run git, as well as when it runs bash.exe to interpret hooks. If either of those features are used on Windows, a malicious git.exe or bash.exe may be run from an untrusted repository. This issue has been patched in version 3.1.41.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing