Vulnerability in simple-git Plugin Allows Execution of Malicious Git Operations
CVE-2026-102826

8.1HIGH

Key Information:

Vendor

Steveukx

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102826?

The simple-git plugin for Node.js allows applications to perform Git operations, but prior to version 4.0.0, it has a vulnerability stemming from the default blockUnsafeOperationsPlugin not completely rejecting configuration includes. This flaw allows an attacker to load a malicious configuration file during the execution of git.clone() when certain custom arguments are provided. Such configurations could enable potentially dangerous commands to be executed with the privileges of the Node.js process. Remediation has been implemented in version 4.0.0 to address these risks, but applications using older versions must be updated to prevent exploitation.

Affected Version(s)

git-js < 4.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.