Oct 6, 2026·6 min read·6 visits
A flaw in simple-git permits attackers to inject malicious arguments via conditional Git configuration rules (includeIf) and abbreviated CLI options, leading to remote code execution.
CVE-2026-102826 is a critical security vulnerability discovered in the simple-git library for Node.js, affecting all versions prior to v4.0.0. The vulnerability allows remote attackers to bypass the library's built-in argument validation rules using conditional configuration includes and abbreviated Command Line Interface (CLI) options. By injecting custom arguments into Git execution pipelines, an attacker can force the application to load a malicious local configuration file, resulting in arbitrary OS command execution under the privileges of the parent Node.js process.
The simple-git package is a popular Node.js library that provides a high-level programmatic wrapper around the system's Git command-line binary. This library is widely integrated into continuous integration/continuous deployment (CI/CD) orchestrators, automatic repository monitors, and web platforms interacting with version control systems. The primary attack surface exists where developers permit user-influenced inputs, such as URL paths, branch names, or custom command arguments, to be passed directly into programmatic Git operations like git.clone() or git.raw().
To prevent exploitation, simple-git historically implemented a mechanism called blockUnsafeOperationsPlugin to validate inputs and strip hazardous configuration options. Despite these filters, attackers discovered logical omissions in how configuration strings and system-level parameters were analyzed. These omissions allowed unauthenticated input vectors to bypass the screening process and execute arbitrary commands.
The vulnerability is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command). When successfully exploited, the Git process spawns subprocesses that execute commands matching the identity of the host application, representing a severe escalation of privilege risk.
The core flaw stems from three distinct bypass pathways within the blockUnsafeOperationsPlugin module. First, the regex filter inside detect-vulnerable-config-writes.ts was engineered to block common unsafe configuration keys, notably targeting standard writes like include.path. However, the regular expression used a loose wildcard match model: \s*include.path which failed to account for conditional configurations like includeIf.<condition>.path. Because the regex did not enforce strict boundaries, complex string evaluations including directories or wildcards easily slipped past the filter.
Second, the native CLI parser inside Git accepts abbreviated or shorthand variations of standard parameters. For instance, Git interprets --conf as a direct alias for the --config parameter. Because the library's argument scanner strictly monitored for precise literals such as --config, attackers could replace the string with --conf=... to evade the parser completely. When executed, the host Git binary parsed and processed the abbreviated CLI switch as valid, leading to configuration modifications.
Third, prior to version 4.0.0, spawned Git child processes inherited the entire unaltered environment block (process.env) from the parent Node.js application. This design allowed attackers to manipulate critical variables such as HOME or XDG_CONFIG_HOME. By redirecting these environmental paths, attackers could force Git to implicitly look for and load a local malicious configuration file without needing to pass explicit configuration parameters directly on the command line.
The remediation introduced in the simple-git 4.0.0 release addresses all three bypass vectors by implementing defensive-in-depth safeguards. Inside packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts, the developer updated the regular expression logic to intercept the includeIf patterns.
// Refactored unsafe configurations in simple-git v4.0.0
const preventUnsafeConfig = [
preventConfigBuilder('include.path', 'allowUnsafeInclude'),
+ preventExpandedConfigBuilder('includeIf', 'allowUnsafeInclude')
];
function preventExpandedConfigBuilder(config: string, category: VulnerabilityCategory) {
- const regex = new RegExp(`\\s*${config.toLowerCase().replace(/\./g, '(\..+)?\.')}`);
+ const regex = new RegExp(`\\s*${config.toLowerCase().replace(/\./g, '(..+)?\.')}`);
return preventConfigBuilder(regex, category, config);
}To prevent command interpretation bypasses via abbreviated options, the library dynamically injects the GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS=true environment variable into spawned child processes. This forces the underlying Git binary to error out and terminate whenever an ambiguous or shortened parameter is used on the CLI.
// Injection in simple-git/src/lib/plugins/allow-environment.plugin.ts
return {
...spawnOptions,
env: {
...env,
GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS: String(!allowAbbreviatedOptions),
},
};Finally, the environment context is thoroughly sanitized. Instead of forwarding the full environment clone, a default-deny paradigm filters out guarded environmental variables that dictate search paths, such as HOME, EDITOR, or PAGER, effectively preventing attackers from hijacking global configuration files.
// Environment filtering logic inside allow-environment.plugin.ts
for (const key of Object.keys(env)) {
const normalised = key.toLowerCase().trim();
if (!isGuardedEnvKey(normalised) || allowed.has(normalised)) {
continue;
}
if (suppliedKeys.has(normalised)) {
throw new GitPluginError(
undefined,
'allowEnvironment',
`Use of "${key}" is blocked by the environment guard`
);
}
delete env[key];
}To exploit this vulnerability, an attacker must carry out a multi-step attack sequence. First, the attacker places a malicious Git configuration file onto the target file system (e.g., via a standard file upload, file write vulnerability, or repository clone operation). This file is structured to execute arbitrary payloads via triggers such as the fsmonitor configuration hook.
# Saved as /tmp/evil.gitconfig
[core]
fsmonitor = touch /tmp/pwnedNext, the attacker locates an API endpoint that feeds custom command-line arguments to the simple-git instance. The attacker sends a request payload that triggers the Git executable with the crafted bypass options. The payload uses both the shorthand parameter bypass and the conditional includeIf structure to avoid trigger detection:
--conf=includeIf.gitdir:/**.path=/tmp/evil.gitconfig
When the Node.js application executes the Git wrapper, the argument validation engine fails to flag --conf or includeIf. The Git process starts, expands the shorthand --conf to --config, and parses the condition gitdir:/**. Because the wildcard matches the temporary Git working directory, Git loads the nested /tmp/evil.gitconfig file. When the execution phase attempts file monitoring actions, it calls the program defined in core.fsmonitor, executing the payload.
The severity of CVE-2026-102826 is designated as High (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) with a base score of 8.1. The attack vector is Network (AV:N), as a remote adversary can trigger the exploit sequence if the web application exposes argument endpoints. However, because the exploit requires placing a local configuration file on the system, the attack complexity is High (AC:H).
The impact on confidentiality, integrity, and availability is High (C:H/I:H/A:H). Successful execution grants the attacker system privileges identical to the hosting Node.js server. An attacker can read databases, exfiltrate API tokens, access sensitive files, or completely crash the application infrastructure.
Due to the ubiquity of simple-git in build pipelines and continuous integration tooling, the risk extends beyond standard application scope. If a build runner or developer portal is compromised, an attacker can modify application source code, introduce backdoors, and orchestrate supply chain compromises.
Remediation of the vulnerability requires an immediate upgrade of simple-git to version 4.0.0 or higher. Developers must also verify that transient dependencies, such as @simple-git/argv-parser and @simple-git/args-pathspec, are upgraded to 1.1.1 and 1.0.4 respectively.
Where upgrades cannot be immediately applied, developers can mitigate risks by altering how they invoke Git commands. Avoid passing unvalidated input arrays or custom arguments directly into underlying execution methods like git.raw(). Rely exclusively on high-level library functions where parameters are passed as structured arguments rather than raw string structures.
In addition, defensive policies can be enforced on systems. Restrict the directories where Git binaries can execute, block the creation of unexpected files in temporary directories, and implement runtime application firewalls to block strings matching inline config signatures:
\b-c\s+include(If)?\..*\.path\bCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
simple-git steveukx | < 4.0.0 | 4.0.0 |
@simple-git/argv-parser steveukx | < 1.1.1 | 1.1.1 |
@simple-git/args-pathspec steveukx | < 1.0.4 | 1.0.4 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-77, CWE-78 |
| Attack Vector | Network |
| CVSS v3.1 Score | 8.1 |
| EPSS Score | 0.0046 (Percentile: 37.65%) |
| Exploit Status | poc |
| CISA KEV Status | Not Listed |
Improper neutralization of special elements used in a command allow an attacker to bypass filters and execute command strings.
A critical host injection vulnerability exists in PyMongo's connection string parser prior to version 4.18.2. The parser globally decodes percent-encoded characters in the host portion before splitting on delimiters, allowing attackers to inject arbitrary servers into the database client's connection pool.
An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.
CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.
A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.
A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.
A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.