CVE-2026-102828

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-30: 109-30
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨Critical - simple-git Git Trailer .cmd Bypass to Command Exec (CVE-2026-102828) simple-git’s default blockUnsafeOperationsPlugin misses trailer tokens ending in .cmd, letting unsafe config through via SimpleGitOptions.config or inline -c args. When git interpret-trailers processes the configured trailer, Git executes an attacker-chosen shell command as the Node.js process. Apps not forwarding attacker-controlled config/-c are not impacted. 👉Affected: simple-git < 4.0.1 | Upgrade to 4.0.1

    0000036
    309 followersView on X

Explore more