
🚨HIGH - simple-git push arg filter bypass via long-option abbreviations (CVE-2026-102827) In simple-git <4.0.0, the default blockUnsafeOperationsPlugin only matches full dangerous option spellings, but Git accepts unambiguous long-option abbreviations. Attacker-supplied abbreviated push args (e.g., --rece/--exe for --receive-pack/--exec) can bypass checks and make git invoke an attacker-chosen command when apps pass through push arguments. 👉Affected: simple-git < 4.0.0 | Upgrade to 4.0.0

