Vulnerability in simple-git Plugin Allows Execution of Malicious Git Operations
CVE-2026-102826
8.1HIGH
What is CVE-2026-102826?
The simple-git plugin for Node.js allows applications to perform Git operations, but prior to version 4.0.0, it has a vulnerability stemming from the default blockUnsafeOperationsPlugin not completely rejecting configuration includes. This flaw allows an attacker to load a malicious configuration file during the execution of git.clone() when certain custom arguments are provided. Such configurations could enable potentially dangerous commands to be executed with the privileges of the Node.js process. Remediation has been implemented in version 4.0.0 to address these risks, but applications using older versions must be updated to prevent exploitation.
Affected Version(s)
git-js < 4.0.0
