PT-2026-102811 · Npm · Simple-Git

·

CVE-2026-102827

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions simple-git versions prior to 4.0.0
Description The default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings, but Git accepts unambiguous long-option abbreviations. This allows attacker-influenced push arguments, such as abbreviated forms of --receive-pack or --exec, to bypass the detectVulnerableFlags function. Consequently, Git may invoke an attacker-selected command when these arguments are passed to a local or file remote, or an attacker-influenced receive-pack target.
Recommendations Update to version 4.0.0.

Fix

Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102827

Affected Products

Simple-Git