DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102826: CVE-2026-102826: Argument Validation Bypass and Command Injection in simple-git

CVE-2026-102826: Argument Validation Bypass and Command Injection in simple-git

Vulnerability ID: CVE-2026-102826
CVSS Score: 8.1
Published: 2026-10-05

CVE-2026-102826 is a critical security vulnerability discovered in the simple-git library for Node.js, affecting all versions prior to v4.0.0. The vulnerability allows remote attackers to bypass the library's built-in argument validation rules using conditional configuration includes and abbreviated Command Line Interface (CLI) options. By injecting custom arguments into Git execution pipelines, an attacker can force the application to load a malicious local configuration file, resulting in arbitrary OS command execution under the privileges of the parent Node.js process.

TL;DR

A flaw in simple-git permits attackers to inject malicious arguments via conditional Git configuration rules (includeIf) and abbreviated CLI options, leading to remote code execution.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-77, CWE-78
  • Attack Vector: Network
  • CVSS v3.1 Score: 8.1
  • EPSS Score: 0.0046 (Percentile: 37.65%)
  • Exploit Status: poc
  • CISA KEV Status: Not Listed

Affected Systems

  • simple-git
  • @simple-git/argv-parser
  • @simple-git/args-pathspec
  • simple-git: < 4.0.0 (Fixed in: 4.0.0)
  • @simple-git/argv-parser: < 1.1.1 (Fixed in: 1.1.1)
  • @simple-git/args-pathspec: < 1.0.4 (Fixed in: 1.0.4)

Code Analysis

Commit: 98864c6

Fix argument verification rules, isolate environment, and block conditional configurations.

Exploit Details

  • GitHub: Integration test configurations detail how to bypass the plugin with include.path and conditional inclusions.

Mitigation Strategies

  • Upgrade simple-git to version 4.0.0 or higher immediately.
  • Avoid passing custom or user-influenced command-line arguments to lower-level execution APIs.
  • Cleanse and restrict the runtime execution environment of the Node.js application process.

Remediation Steps:

  1. Update the project dependencies using your package manager: npm install simple-git@latest or yarn upgrade simple-git.
  2. Audit the codebase to identify usage of raw CLI input fields mapped to simple-git methods.
  3. Deploy process-level logging to capture spawned Git binary arguments in production environments.

References


Read the full report for CVE-2026-102826 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)