Remote Code Execution Vulnerability in Simple-Git by SteveUKX
CVE-2022-25860
9.8CRITICAL
What is CVE-2022-25860?
The simple-git package prior to version 3.16.0 is susceptible to Remote Code Execution (RCE) due to ineffective input sanitization in its clone(), pull(), push(), and listRemote() methods. This issue originates from an incomplete resolution of a previously identified vulnerability, highlighting a significant security risk for developers using this package.
Affected Version(s)
simple-git 0 < 3.16.0
