Npm · Simple-Git · CVE-2026-102827
**Name of the Vulnerable Software and Affected Versions**
simple-git versions prior to 4.0.0
**Description**
The default `blockUnsafeOperationsPlugin` compares parsed option names with literal dangerous option spellings, but Git accepts unambiguous long-option abbreviations. This allows attacker-influenced push arguments, such as abbreviated forms of `--receive-pack` or `--exec`, to bypass the `detectVulnerableFlags` function. Consequently, Git may invoke an attacker-selected command when these arguments are passed to a local or file remote, or an attacker-influenced receive-pack target.
**Recommendations**
Update to version 4.0.0.