PT-2026-102811 · Npm · Simple-Git
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
simple-git versions prior to 4.0.0
Description
The default
blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings, but Git accepts unambiguous long-option abbreviations. This allows attacker-influenced push arguments, such as abbreviated forms of --receive-pack or --exec, to bypass the detectVulnerableFlags function. Consequently, Git may invoke an attacker-selected command when these arguments are passed to a local or file remote, or an attacker-influenced receive-pack target.Recommendations
Update to version 4.0.0.
Fix
Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple-Git