DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102828: CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

Vulnerability ID: CVE-2026-102828
CVSS Score: 9.2
Published: 2026-10-05

A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.

TL;DR

Incomplete configuration blocklists and argument parsing discrepancies in simple-git prior to version 4.0.1 allow remote attackers to achieve arbitrary shell command execution via trailer commands and rebase parameters.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-78, CWE-184
  • Attack Vector: Network
  • CVSS Base Score: 9.2 (Critical)
  • EPSS Score: 0.00275 (0.27% probability of exploitation)
  • Exploit Status: Proof-of-Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • Node.js applications integrating simple-git prior to version 4.0.1
  • simple-git: >= 3.15.0, < 4.0.1 (Fixed in: 4.0.1)

Code Analysis

Commit: d762810

Fix: blockUnsafeOperationsPlugin bypasses on trailer configurations and rebase options

Mitigation Strategies

  • Upgrade simple-git to version 4.0.1 or higher immediately.
  • Enforce strict options configuration disabling all unsafe command binaries and exec configurations.
  • Apply strict input validation blocklists or allowlists on all properties passed to simple-git configuration parameters.

Remediation Steps:

  1. Identify all Node.js projects utilizing the npm package simple-git.
  2. Update package dependencies in package.json to reflect simple-git version >= 4.0.1.
  3. Verify that simpleGit options do not explicitly set allowUnsafeCommandBinaries or allowUnsafeExec to true.
  4. Run regression tests on applications using the library to confirm compatibility with the 4.0.1 engine.

References


Read the full report for CVE-2026-102828 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)