Remote Command Execution Vulnerability in SimpleGit by Node.js Vendor
CVE-2026-102828
9.2CRITICAL
What is CVE-2026-102828?
A vulnerability in SimpleGit affects versions from 3.15.0 to 4.0.1, where it does not classify the trailer..cmd configuration as unsafe. This allows an attacker to pass malicious commands through SimpleGitOptions.config or inline -c arguments, leading to arbitrary command execution on the host operating system with the privileges of the Node.js process. Users are encouraged to upgrade to version 4.0.1 or later to mitigate risks associated with this vulnerability.
Affected Version(s)
git-js >= 3.15.0, < 4.0.1
