PT-2026-102812 · Npm · Simple-Git
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
simple-git versions 3.15.0 through 4.0.0
Description
The default
blockUnsafeOperationsPlugin fails to classify trailer.<token>.cmd as an unsafe configuration. This allows an attacker to execute arbitrary shell commands with the operating-system identity and permissions of the Node.js process if the application passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments. The execution occurs when git interpret-trailers processes the configured trailer.Recommendations
Update simple-git to version 4.0.1.
Fix
OS Command Injection
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple-Git