Remote Command Execution Vulnerability in SimpleGit by Node.js Vendor
CVE-2026-102828

9.2CRITICAL

Key Information:

Vendor

Steveukx

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102828?

A vulnerability in SimpleGit affects versions from 3.15.0 to 4.0.1, where it does not classify the trailer..cmd configuration as unsafe. This allows an attacker to pass malicious commands through SimpleGitOptions.config or inline -c arguments, leading to arbitrary command execution on the host operating system with the privileges of the Node.js process. Users are encouraged to upgrade to version 4.0.1 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

git-js >= 3.15.0, < 4.0.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.