
CVE-2026-6951 is a critical vulnerability associated with the simple-git package. It allows an attacker to perform Remote Code Execution (RCE) due to an incomplete fix for a previous vulnerability (CVE-2022-25912). The amusing part is that CVE-2022-25912 was fixed by blocking the -c option, which resulted in the emergence of CVE-2026-6951 because the ---config option was not blocked. If untrusted data can reach the options argument passed to simple-git, an attacker can achieve remote code execution by enabling the protocol.ext.allow=always parameter and using an ext:: clone source. PoC is available on GitHub https://github.com/binautopsy/research-labs/blob/main/cve-2026-6951/exploit.js #exploit #cve #vulnerability #poc #github
Post summary
CVE‑2026‑6951 is a critical RCE flaw in simple‑git, with a publicly available PoC script on GitHub, but there is no evidence of active exploitation or an available patch.

