All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.
https://security.snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858
https://security.gentoo.org/glsa/202311-01
https://lists.debian.org/debian-lts-announce/2023/07/msg00024.html