Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-102828: simple-git may run attacker-chosen commands
CVE-2026-102828 · published 12 days ago
Summary
Versions of simple-git from 3.15.0 up to 4.0.0 let a program pass configuration values that can cause Git to execute a shell command chosen by an attacker. This command runs with the same rights as the Node.js application, potentially exposing the system. Update simple-git to version 4.0.1 or later to stop this behavior.
What to do
- Update simple-git to version 4.0.1.
- Update simple-git_project simple-git to version 4.0.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | steveukx | git-js | >= 3.15.0, < 4.0.1 |
| npm | – | simple-git |
>= 3.15.0, < 4.0.1 Fix: upgrade to 4.0.1
|
| – | simple-git_project | simple-git |
>= 3.15.0, < 4.0.1 cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* |
Original advisory text
simple-git unsafe-operation guard does not block trailer command configuration
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.
References
- https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh Vendor Advisory
- https://github.com/steveukx/git-js/pull/1198 Patch
- https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1... Patch
- https://github.com/steveukx/git-js/releases/tag/[email protected] URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-1028... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-102828 Vendor Advisory
- https://github.com/advisories/GHSA-x6jw-m9v5-85vh
- https://github.com/steveukx/git-js Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-78OS Command Injection
CWE-184Incomplete List of Disallowed Inputs
Timeline
Published29 Sep 2026
Updated10 Oct 2026
First seen29 Sep 2026
Sources
CVE-2026-102828 · NVD
CVE-2026-102828 · MITRE
CVE-2026-102828 · OSV
GHSA-x6jw-m9v5-85vh · GHSA
GHSA-x6jw-m9v5-85vh · OSV
Track software like this
Free during beta