๐Ÿ” CVE Alert

CVE-2026-102828

UNKNOWN 0.0

simple-git unsafe-operation guard does not block trailer command configuration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.

CWE CWE-78 CWE-184
Vendor steveukx
Product git-js
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for steveukx git-js

Be the first to know when new unknown vulnerabilities affecting steveukx git-js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

steveukx / git-js
>= 3.15.0, < 4.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh github.com: https://github.com/steveukx/git-js/pull/1198 github.com: https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3 github.com: https://github.com/steveukx/git-js/releases/tag/[email protected]