Oct 6, 2026·7 min read·5 visits
A validation mismatch allows command execution bypasses in simple-git by using abbreviated Git options such as --receive-p and --exe, which bypass blocklist filters but are fully executed by the underlying Git binary.
CVE-2026-102827 is an argument injection bypass vulnerability in the node.js simple-git package where the default blockUnsafeOperationsPlugin fails to detect abbreviated Git command options. Attackers can bypass validations using prefixes like --receive-p or --exe, which native Git subsequently expands to dangerous options, leading to remote command execution.
This section outlines the architectural role of simple-git and the mechanics of the identified argument injection vulnerability. The simple-git library serves as a lightweight interface running Git commands within Node.js applications by wrapping process spawns. While it simplifies repository operations, exposing argument vectors to untrusted input introduces an attack surface where malicious parameters can modify execution logic.
To control this risk, the library employs security plugins designed to filter out destructive parameters. However, differences in how the Node.js wrapper parses options compared to the native C-based Git binary create a discrepancy. This mismatch allows command execution via argument injection, specifically bypassing prefix checks within the blockUnsafeOperationsPlugin.
This vulnerability is tracked as CVE-2026-102827 and GHSA-858h-whjf-mvg5. It is classified as improper neutralization of argument delimiters (CWE-88) and command injection (CWE-77). The flaw permits unauthenticated remote command execution under the context of the running application, specifically targeting the unprotected push path.
The root cause of this vulnerability lies in a parsing discrepancy between the JavaScript-based argument validation logic in simple-git and the native command-line option parser implemented in the git binary. The simple-git library uses a blocklist pattern via its blockUnsafeOperationsPlugin to inspect command arguments before executing them. This plugin attempts to prevent abuse by comparing input strings against known dangerous option patterns, such as --receive-pack and --exec.
The native Git CLI parser utilizes an option processing engine that automatically resolves unambiguous long-form parameter prefixes to their full counterparts. If a developer runs git push --receive-p=CMD, the parser recognizes that --receive-p matches only one valid option prefix, which is --receive-pack. It automatically expands the abbreviation internally and executes the argument accordingly. The same mechanism applies to --exe resolving to --exec.
Because simple-git's blockUnsafeOperationsPlugin historically performed exact string matches or restrictive regular expression checks, it did not account for these abbreviation permutations. An attacker could supply --receive-p or --exe instead of the fully written option names. The validation filter evaluated these strings, determined they did not match the blocked literals, and passed them to the child process spawning layer.
Upon receiving the command line, the native Git process parsed the abbreviated options and executed the specified binary payloads. Although previous fixes, such as those addressing CVE-2026-28291, introduced mitigation steps for specific operations like cloning, they failed to cover the push path. Consequently, the push path remained fully exposed to this parsing bypass mechanism.
The vulnerable implementation of simple-git relied on matching literal string patterns within its input validation checks. The following conceptual representation shows the vulnerable validation path where options were checked against exact strings:
// Vulnerable validation logic (conceptual)
function detectVulnerableFlags(args) {
const dangerousFlags = ['--receive-pack', '--exec', '--upload-pack'];
for (const arg of args) {
if (dangerousFlags.includes(arg.split('=')[0])) {
throw new Error('Unsafe operation blocked');
}
}
}The patched implementation in version 4.0.0 leverages an internal Git configuration variable rather than maintaining a complex local JavaScript parser. It sets the GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS environment variable to "true" inside the child process execution context. This prevents the native Git binary from resolving abbreviated arguments, forcing it to reject any incomplete long-form options.
The patch introduces the environment plugin to enforce this constraint globally:
// simple-git/src/lib/plugins/allow-environment.plugin.ts
export function allowEnvironmentPlugin(
allowEnvironment: readonly string[],
allowAbbreviatedOptions = false
): SimpleGitPlugin<'spawn.options'> {
return {
type: 'spawn.options',
action(spawnOptions, context) {
const env = { ...spawnOptions.env };
return {
...spawnOptions,
env: {
...env,
GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS: String(!allowAbbreviatedOptions),
},
};
},
};
}If an abbreviated parameter is supplied when GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS is set to "true", Git immediately halts execution and exits with status code 128. The wrapper captures this error and handles it gracefully via a specialized exception handler.
// simple-git/src/lib/errors/git-configuration-error.ts
const REASONS = {
DISALLOWED_ABBREVIATED: {
text: 'disallowed abbreviated or ambiguous option',
solution:
'Unambiguous abbreviated options blocked with unsafe.allowAbbreviatedOptions setting: {message}',
},
UNKNOWN: { text: '~ unknown ~', solution: undefined },
} as const;This structural change shifts the responsibility of validating command-line options back to the Git binary itself, ensuring full completeness of the fix across all present and future CLI options.
To exploit this vulnerability, an attacker must identify a consumer application that accepts user-supplied arguments and passes them directly to simple-git methods, specifically the push operation. The application must permit untrusted string inputs to populate the options or arguments arrays of the library wrapper.
An attacker constructs a payload targeting the push operation by leveraging the --receive-p or --exe option abbreviations. The payload is designed to point to an arbitrary local command execution string, formatted as an option assignment.
# Example command executed via child process spawn
git push origin main --receive-p="touch /tmp/pwned"When this command runs, the Node.js process spawns the native Git binary. The Git command-line parser maps --receive-p to the native --receive-pack handler. Since --receive-pack directs Git to use a specific helper executable to receive objects on the remote side, Git executes the specified payload string as an operating system command under the privileges of the Node.js application process.
The impact of successful exploitation is remote command execution (RCE) on the host operating system. Because the payload runs as a child process of the Node.js application, the injected commands execute with the same operating system privileges as the parent Node.js runtime process. If the application runs as a privileged user or root, the attacker gains full administrative control over the host container or server.
The CVSS 3.1 base score is 8.1, reflecting high confidentiality, integrity, and availability impacts. The attack complexity is rated as high because the exploit requires a specific application configuration where user-controlled inputs are passed directly into the command options arrays of simple-git methods.
While the Exploit Prediction Scoring System (EPSS) score remains low at approximately 0.36%, the simplicity of abusing prefix abbreviations makes this a highly reliable exploitation vector once the prerequisite input exposure is met. There are no active reports of this vulnerability being used in ransomware or listed in the CISA KEV catalog, but the availability of public technical details increases the risk of targeted scanning.
The primary mitigation is upgrading the simple-git dependency to version 4.0.0 or higher. This version activates the native blocking of abbreviated options by default across all spawned Git sub-processes. Applications using legacy versions must be audited to ensure that user input is never used to construct option flags.
If upgrading is not immediately possible due to breaking changes in major version releases, developers must implement manual input sanitization. A strict validation filter must be applied to all user-controlled strings, blocking any parameter that starts with a hyphen character (-) unless it explicitly matches a predefined safe allowlist of non-option values.
Additionally, applying container-level security controls reduces the potential blast radius. Applications should execute within minimal, unprivileged service accounts, and system-call filtering such as seccomp or AppArmor should be configured to restrict the creation of unauthorized child processes.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
simple-git steveukx | < 4.0.0 | 4.0.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-88, CWE-77 |
| Attack Vector | Network |
| CVSS Base Score | 8.1 |
| Exploit Maturity | PoC |
| Affected Component | blockUnsafeOperationsPlugin |
| Remediation Strategy | GIT_TEST_DISALLOW_ABBREVIATED_OPTIONS |
The product takes string input from an external source, constructs a command string with arguments from it, and executes the command. However, it does not properly neutralize command or argument delimiters.
A critical host injection vulnerability exists in PyMongo's connection string parser prior to version 4.18.2. The parser globally decodes percent-encoded characters in the host portion before splitting on delimiters, allowing attackers to inject arbitrary servers into the database client's connection pool.
An integer overflow vulnerability exists in PyMongo's bundled C extension (bson/buffer.c) when serializing abnormally large documents. Due to compiler optimizations utilizing standard C Undefined Behavior rules, memory overflow validation checks are completely removed during compilation, enabling an attacker to trigger a heap-based out-of-bounds write.
CVE-2026-102826 is a critical security vulnerability discovered in the simple-git library for Node.js, affecting all versions prior to v4.0.0. The vulnerability allows remote attackers to bypass the library's built-in argument validation rules using conditional configuration includes and abbreviated Command Line Interface (CLI) options. By injecting custom arguments into Git execution pipelines, an attacker can force the application to load a malicious local configuration file, resulting in arbitrary OS command execution under the privileges of the parent Node.js process.
A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.
A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.
A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.