Known Vulnerabilities for Git-shell by Git
Listed below are 1 of the newest known vulnerabilities associated with "Git-shell" by "Git".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56075 json | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_m... | Not Provided | 2026-06-18 | 2026-06-22 |
| CVE-2026-56074 json | PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent e... | Not Provided | 2026-06-18 | 2026-06-22 |
| CVE-2026-55748 json | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with ... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-55743 json | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-55249 json | @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-55201 json | Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that ... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-54686 json | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accept... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-54555 json | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did n... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-54420 json | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by ... | Not Provided | 2026-06-14 | 2026-06-16 |
| CVE-2026-54230 json | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write o... | Not Provided | 2026-06-13 | 2026-06-15 |