Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2022-25860: simple-git may allow unauthorized code execution
CVE-2022-25860 · published 3 days ago
Summary
The simple-git library used in several projects could let an attacker run their own code on your system. This risk has been fixed in newer releases, and the updates are already published. Upgrade to the latest version of simple-git to stay protected.
What to do
- Update GitHub Actions simple-git to version 3.16.0.
- Update simple-git to version 3.16.0-aikido.1.
- Update rootio @rootio/simple-git to version 3.16.0-root.io.1.
- Update simple-git_project simple-git to version 3.16.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | simple-git |
< 3.16.0 Fix: upgrade to 3.16.0
|
| – | simple-git_project | simple-git |
< 3.16.0 cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* |
| Root:npm | – | simple-git |
< 3.16.0-aikido.1 Fix: upgrade to 3.16.0-aikido.1
|
| Root:npm | rootio | @rootio/simple-git |
< 3.16.0-root.io.1 Fix: upgrade to 3.16.0-root.io.1
|
Original advisory text
CVE-2022-25860 in simple-git - Patched by Root
Root has patched CVE-2022-25860 in the simple-git package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25860
- https://github.com/steveukx/git-js/pull/881/commits/95459310e5b8f96e20bb77ef1a65...
- https://github.com/steveukx/git-js/commit/ec97a39ab60b89e870c5170121cd9c1603cc19...
- https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3177391
- https://github.com/advisories/GHSA-9w5j-4mwv-2wj8
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-78OS Command Injection
CWE-94Code Injection
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta