Fedora 44 : python-mkdocs-git-revision-date-localized-plugin (2026-c10d41473a)

high Nessus Plugin ID 341803

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 44 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2026-c10d41473a advisory.

Update to v1.5.4 a2313a3 Security Raises the gitpython floor from >=3.1.44 to >=3.1.59.

Earlier dependabot bumps only touched this repo's uv.lock, which pins the CI environment and nothing else. Downstream users installing from PyPI resolved against pyproject.toml, so they could still land on a GitPython carrying the 2026 option-injection advisories GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr among them, all patched by 3.1.58, with further option hardening in 3.1.59.

This plugin never passes user input as git options, so it was not exploitable through those. The floor bump forces the upgrade in environments that already hold an older GitPython, and clears the warnings downstream scanners report.

Thanks to @nucleus-ffm for reporting it in #222.

Maintenance Harden test git repos against flaky Error building trees failures by @timvink in #212 ci: update GitHub Actions to Node 24 compatible versions by @timvink in #213 deps: bump idna and pymdown-extensions to patch security alerts by @timvink in #214 Bump gitpython from 3.1.50 to 3.1.58 in #217, #219, #220 Bump pymdown-extensions from 10.21.3 to 11.0.1 in #218, #221


Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected python-mkdocs-git-revision-date-localized-plugin package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-c10d41473a

Plugin Details

Severity: High

ID: 341803

File Name: fedora_2026-c10d41473a.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/31/2026

Updated: 8/31/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:44, p-cpe:/a:fedoraproject:fedora:python-mkdocs-git-revision-date-localized-plugin

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/21/2026

Vulnerability Publication Date: 8/21/2026

Reference Information