CVE-2026-102827

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-30: 209-30
Referenced assets1 URL
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - simple-git push arg filter bypass via long-option abbreviations (CVE-2026-102827) In simple-git <4.0.0, the default blockUnsafeOperationsPlugin only matches full dangerous option spellings, but Git accepts unambiguous long-option abbreviations. Attacker-supplied abbreviated push args (e.g., --rece/--exe for --receive-pack/--exec) can bypass checks and make git invoke an attacker-chosen command when apps pass through push arguments. 👉Affected: simple-git < 4.0.0 | Upgrade to 4.0.0

    0000040
    309 followersView on X
  • NewNormal Security@NewScanTeam

    NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 30 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Command execution via git arguments in a Node app — an attacker's command runs as the app (simple-git CVE-2026-102828, CVE-2026-102826, CVE-2026-102827) 📦 HTTP client stalled by the server it calls — hangs forever, eats memory, or skips proxy TLS checks (urllib3 CVE-2026-97689, CVE-2026-97687, CVE-2026-97688) 🖥️ Static-site generator's dev server left exposed — whole config readable, files rewritable, no login (Marmite CVE-2026-102811, CVE-2026-102810) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    0000027
    6 followersView on X

Explore more