Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2022-25860: simple-git may allow unauthorized code execution

CVE-2022-25860 · published 3 days ago
Summary

The simple-git library used in several projects could let an attacker run their own code on your system. This risk has been fixed in newer releases, and the updates are already published. Upgrade to the latest version of simple-git to stay protected.

What to do
  • Update GitHub Actions simple-git to version 3.16.0.
  • Update simple-git to version 3.16.0-aikido.1.
  • Update rootio @rootio/simple-git to version 3.16.0-root.io.1.
  • Update simple-git_project simple-git to version 3.16.0 or later.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions simple-git < 3.16.0
Fix: upgrade to 3.16.0
– simple-git_project simple-git < 3.16.0
cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:*
Root:npm – simple-git < 3.16.0-aikido.1
Fix: upgrade to 3.16.0-aikido.1
Root:npm rootio @rootio/simple-git < 3.16.0-root.io.1
Fix: upgrade to 3.16.0-root.io.1
Original advisory text
CVE-2022-25860 in simple-git - Patched by Root
Root has patched CVE-2022-25860 in the simple-git package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
3% chance of attack within 30 days
Type
CWE-78OS Command Injection
CWE-94Code Injection
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta