
🚨Critical - simple-git Git Trailer .cmd Bypass to Command Exec (CVE-2026-102828) simple-git’s default blockUnsafeOperationsPlugin misses trailer tokens ending in .cmd, letting unsafe config through via SimpleGitOptions.config or inline -c args. When git interpret-trailers processes the configured trailer, Git executes an attacker-chosen shell command as the Node.js process. Apps not forwarding attacker-controlled config/-c are not impacted. 👉Affected: simple-git < 4.0.1 | Upgrade to 4.0.1
