GHSA-h6m2-r6h9-4c44
CRITICALCVE-2025-10283bbot's gitdumper.py insufficiently sanitises a .git/config file, leading to Remote Code Execution (RCE).
- Affected
- < 2.7.0
- Fixed in
- 2.7.0
- Weakness
- CWE-22
- Published
- 2025-10-09
- Source
- github
8 known vulnerabilities, worst severity CRITICAL.
how bad it is if exploited, out of 10
chance of exploitation in the next 30 days
CyberXYZ composite, out of 10
fig. 01 — GHSA-h6m2-r6h9-4c44, the advisory selected below
45 direct, 22 carrying known advisories, worst CRITICAL
No published models are known to use this package.
Checked 2026-09-22 at 01:44 UTC. The most recent advisory here was published 2026-06-18. Updated continuously from NVD, GHSA, OSV and CNA feeds.