Command Injection Vulnerability in Simple-Git by SteveUKX
CVE-2026-102827
8.1HIGH
What is CVE-2026-102827?
The simple-git package, which facilitates running Git commands in Node.js applications, has a vulnerability prior to version 4.0.0 that allows attacker-influenced arguments to bypass security checks during Git operations. This can lead to command injection risks, enabling attackers to execute arbitrary commands on the host system through manipulated Git push actions that leverage ambiguously defined Git options. The vulnerability primarily arises from inadequate validation of Git option names against unambiguous long-option abbreviations. Users are encouraged to upgrade to version 4.0.0 or later to mitigate this risk.
Affected Version(s)
git-js < 4.0.0
