CVE-2026-102827: Command and Argument Injection Bypass in simple-git via Option Abbreviation
Vulnerability ID: CVE-2026-102827
CVSS Score: 8.1
Published: 2026-10-05
CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.
TL;DR
A validation mismatch allows command execution bypasses in simple-git by using abbreviated Git options such as --receive-p and --exe, which bypass blocklist filters but are fully executed by the underlying Git binary.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-88, CWE-77
- Attack Vector: Network
- CVSS Base Score: 8.1
- Exploit Maturity: PoC
- Affected Component: blockUnsafeOperationsPlugin
- Remediation Strategy: GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS
Affected Systems
- Node.js environments deploying applications that integrate simple-git versions prior to 4.0.0
- Systems executing server-side simple-git commands where parameters are derived from user-controlled inputs
-
simple-git: < 4.0.0 (Fixed in:
4.0.0)
Code Analysis
Commit: 98864c6
Introduce allowEnvironmentPlugin and restrict abbreviated options using GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS
Mitigation Strategies
- Upgrade simple-git to 4.0.0 or later to enable native abbreviation restriction.
- Perform strict validation on user-supplied options, rejecting strings starting with a hyphen (-) unless matched against an allowlist.
- Restrict execution context using container-level isolation and minimal privilege user configurations.
Remediation Steps:
- Identify current simple-git version by running: npm list simple-git
- Update simple-git dependency in package.json to at least ^4.0.0
- Run npm install to pull down the patched package
- Verify that custom arguments are not explicitly utilizing dangerous abbreviation overrides in application code
References
Read the full report for CVE-2026-102827 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)