CVE-2026-102828
simple-git unsafe-operation guard does not block trailer command configuration
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.
| CWE | CWE-78 CWE-184 |
| Vendor | steveukx |
| Product | git-js |
| Published | Sep 29, 2026 |
Get instant alerts for steveukx git-js
Be the first to know when new unknown vulnerabilities affecting steveukx git-js are published โ delivered to Slack, Telegram or Discord.