Vulnerability GHSA-hffm-xvc3-vprc
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
5 months ago
April 25, 2026 at 06:30 AM UTC
simple-git is vulnerable to Remote Code Execution
0.0.1 - 3.35.2
0.0.1 - 3.35.2
Summary
simple-git is vulnerable to Remote Code Execution
Details
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
8 hours ago
simple-git unsafe-operation guard does not block trailer command configuration
3.15.0 - 4.0.0 GHSA-x6jw-m9v5-85vh
3.15.0 - 4.0.0 GHSA-x6jw-m9v5-85vh
High Risk
8 hours ago
simple-git allows command execution through unblocked Git configuration includes
0.0.1 - 3.36.0 GHSA-g4wm-2vf7-vfgr
0.0.1 - 3.36.0 GHSA-g4wm-2vf7-vfgr
High Risk
8 hours ago
simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
0.0.1 - 3.36.0 GHSA-858h-whjf-mvg5
0.0.1 - 3.36.0 GHSA-858h-whjf-mvg5
High Risk
5 months ago
simple-git Affected by Command Execution via Option-Parsing Bypass
0.0.1 - 3.31.1 GHSA-jcxm-m3jx-f287
0.0.1 - 3.31.1 GHSA-jcxm-m3jx-f287
Critical
6 months ago
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
3.15.0 - 3.32.2 GHSA-r275-fr43-pm7q
3.15.0 - 3.32.2 GHSA-r275-fr43-pm7q
Impacted packages
Timeline
Published
5 months ago
April 25, 2026 at 06:30 AM UTC
Fixed (3.36.0)
5 months ago
April 12, 2026 at 05:33 AM UTC
Last Modified
26 days ago
September 10, 2026 at 03:51 AM UTC