Vulnerability GHSA-hffm-xvc3-vprc

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
5 months ago
April 25, 2026 at 06:30 AM UTC
simple-git is vulnerable to Remote Code Execution
0.0.1 - 3.35.2
0.0.1 - 3.35.2

Summary

simple-git is vulnerable to Remote Code Execution

Details

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

Impacted packages

Timeline

Published
5 months ago
April 25, 2026 at 06:30 AM UTC
Fixed (3.36.0)
5 months ago
April 12, 2026 at 05:33 AM UTC
Last Modified
26 days ago
September 10, 2026 at 03:51 AM UTC