CVE-2026-87818 GitPython 3.1.59 fails to restrict the --no-index… — CVE Notify — TG.ME

🚨 CVE-2026-87818
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.

🎖@cveNotify
GitHub
GitPython 3.1.59: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
### Summary GitPython 3.1.59 blocks a previously available local-file read path through unsafe git diff options such as -O/--orderfile. However, the high-level diff API still permits --no-ind...
September 9, 2026 22