CRITICAL 9.2 NVD
CVE-2026-102828
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.
References
- https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3
- https://github.com/steveukx/git-js/pull/1198
- https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1
- https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-29 via NVD.
Risk Timeline
CVE Disclosed2026-09-29 · 0 days ago
Remediation Resources
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.