CVE-2026-28292Disclosure(simple-git_project / simple-git)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch simple-git_project simple-git systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-178CWE-76

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • simple-git

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 30 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 23 signals
  • Disclosure: 19 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 14 mentions (2026-03-11); latest day: 1
  • 30 total mentions across 6 days

Affected systems

Products
simple-git

Deep dive

Activity timeline30 mentions / 6d
0471114Mentions · 2026-03-10: 7Mentions · 2026-03-11: 14Mentions · 2026-03-12: 5Mentions · 2026-03-13: 2Mentions · 2026-03-17: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-03-10: 4PoC Mentioned / Linked · 2026-03-11: 4PoC Mentioned / Linked · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-13: 1Exploit Tool / Code · 2026-03-10: 4Exploit Tool / Code · 2026-03-11: 1Exploit Tool / Code · 2026-03-12: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 2Technical Details · 2026-03-10: 4Technical Details · 2026-03-11: 12Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 2Technical Details · 2026-03-17: 1Technical Details · 2026-04-15: 103-1003-1103-1203-1303-1704-15
Signal classification5 categories
Disclosure
1963.3%
PoC
413.3%
General
310.0%
Exploit
26.7%
Patch
26.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-107
Disclosure2Exploit2Patch1PoC2
2026-03-1114
Disclosure11General1Patch1PoC1
2026-03-125
Disclosure2General2PoC1
2026-03-132
Disclosure2
2026-03-171
Disclosure1
2026-04-151
Disclosure1
Full discourse20 posts
  • Clandestine@akaclandestine
    Disclosure

    CVE-2026-28292: simple-git Remote Code Execution - Case-Sensitivity Bypass (CVSS 9.8) https://www.codeant.ai/security-research/simple-git-remote-code-execution-cve-2026-28292

    Post summary

    The post announces a new high‑severity Remote Code Execution flaw (CVE‑2026‑28292) in simple‑git, giving key technical details and linking to a research page.

    16029143.0K
    56.1K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-28292: RCE in simple-git via case-sensitivity bypass (CVSS 9.8) https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292

    Post summary

    A remote code execution vulnerability (CVSS 9.8) in simple‑git via case‑sensitivity bypass has been disclosed, with technical details and a linked research article.

    1803182.5K
    153.0K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #exploit #AppSec 1⃣. CVE-2026-28292: simple-git RCE - Case-Sensitivity Bypass https://www.codeant.ai/security-research/simple-git-remote-code-execution-cve-2026-28292 // A regex bug in simple-git 3.15.0 - 3.32.3 allows bypassing CVE patches and enables RCE via uppercase protocol variants 2⃣. CVE-2025-12818: https://swarm.ptsecurity.com/attack-arithmetic-how-an-integer-overflow-in-postgresql-libpq-leads-to-denial-of-service Attack arithmetic - how an integer overflow in PostgreSQL libpq leads to DoS // A 2025 PostgreSQL libpq integer overflow in PQescapeInternal allows memory corruption and DoS, affecting applications like PHP's PDO driver 3⃣. CVE-2026-20820: https://cravaterouge.com/articles/cve-2026-20820 Chasing the Ghost in the Log // A heap-based BoF in Windows clfs.sys caused by a length calculation bug, leading to potential system crashes but unlikely to enable privilege escalation

    Post summary

    The tweet lists three CVEs with brief technical details and links to research articles, but it does not provide exploit code, active‑attack evidence, or mitigation guidance.

    0301831.2K
    3.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical RCE vulnerability (CVE-2026-28292) affects `simple-git` due to a `blockUnsafeOperationsPlugin` bypass via `protocol.allow` config. Review input validation. #NodeJS #RCE #SecurityBypass https://www.pulsepatch.io/posts/cve-2026-28292-simple-git-rce-bypass

    Post summary

    The post announces a critical RCE vulnerability in simple‑git, describing the technical bypass but does not provide a PoC, exploit, or patch.

    1000120230
    14 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2026-28292: RCE in simple-git via case-sensitivity bypass (CVSS 9.8) https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292

    Post summary

    A newly disclosed remote code execution vulnerability (CVE‑2026‑28292) in simple‑git allows exploitation via a case‑sensitivity bypass, with a CVSS score of 9.8 and research details linked.

    110123882
    32.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28292: CRITICAL] Critical vulnerability in `simple-git` versions 3.15.0-3.32.2 allows attackers to bypass CVE fixes and gain remote code execution. Update to version 3.23.0 for the fix.#cve,CVE-2026-28292,#cybersecurity https://cvefind.com/CVE-2026-28292

    Post summary

    The tweet announces a critical remote‑code‑execution vulnerability in simple‑git versions 3.15.0‑3.32.2 and recommends users update to version 3.23.0 to remediate the issue.

    12050169
    601 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: A critical case-sensitivity vulnerability (CVE-2026-28292, CVSSv3 9.8) in #simplegit allows an attacker to achieve full remote code execution on the host machine. Time to #Patch #Patch #Patch

    Post summary

    The tweet highlights a new critical case‑sensitivity flaw (CVE‑2026‑28292) in simplegit that permits full remote code execution and urges users to patch immediately.

    03031308
    7.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28292 - Critical `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2... https://www.thehackerwire.com/vulnerability/CVE-2026-28292/ https://t.co/7T0aSamdA3

    Post summary

    The tweet briefly discloses CVE-2026-28292 affecting simple-git, noting a version range and a bypass of prior fixes, but it does not mention a PoC, exploit code, active exploitation, or patches.

    12040163
    133 followersView on X
  • Marius Avram@securityshell
    Disclosure

    CVE-2026-28292: simple-git Remote Code Execution - Case-Sensitivity Bypass (CVSS 9.8) https://www.codeant.ai/security-research/simple-git-remote-code-execution-cve-2026-28292

    Post summary

    A new high‑severity CVE‑2026‑28292, a Remote Code Execution flaw in simple‑git via case‑sensitivity bypass, has been disclosed with CVSS 9.8 and additional details linked in a research article.

    02031377
    16.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28292 `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two p… https://www.cve.org/CVERecord?id=CVE-2026-28292

    Post summary

    CVE‑2026‑28292 affects simple‑git versions 3.15.0‑through‑3.32.2, enabling attackers to bypass certain controls; the announcement focuses on the disclosure of the vulnerability.

    12021348
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28292: simple-git has blockUnsafeOperat... CVE fixes getting bypassed via case-insensitive config parsing - classic sanitization fail that turns Node.js apps into... https://zerodaysignal.com/vulnerability/CVE-2026-28292 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    This tweet alerts on CVE-2026-28292, noting that simple‑git’s patch can be bypassed via case‑insensitive config parsing, with a link provided for further information.

    11030171
    142 followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    General

    https://www.codeant.ai/security-research/simple-git-remote-code-execution-cve-2026-28292

    Post summary

    The input consists solely of a URL link without any explicit information, making it impossible to identify PoC, exploit, patch, or other detailed indicators.

    01021109
    3.2K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-28292: RCE in simple-git via case-sensitivity bypass (CVSS 9.8) https://www.reddit.com/r/netsec/comments/1rqmrer/cve202628292_rce_in_simplegit_via_casesensitivity/

    Post summary

    The post announces CVE-2026-28292, describing a high‑severity remote code execution flaw in simple‑git caused by a case‑sensitivity bypass; no PoC, exploit code, active exploitation, or patch information is provided.

    0202075
    70 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @akaclandestine 12.4M+ affected installations... that's basically half of npm! CVE-2026-28292 in simple-git shows how one case-sensitivity bypass can compromise entire development pipelines. https://vulntracker.io/cves/CVE-2026-28292

    Post summary

    The tweet announces the disclosure of CVE‑2026‑28292 affecting over 12 million npm installations, detailing a case‑sensitivity bypass in simple‑git that could compromise entire development pipelines.

    11010348
    399 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 CVE-2026-28292 in simple-git could allow arbitrary command execution (potential RCE). Update to the patched version ASAP and follow best practices to reduce exploitation risk. 🔍 https://vulert.com/vuln-db/CVE-2026-28292 #CyberSecurity #AppSec #Vulert https://t.co/XVP1ODhPKb

    Post summary

    The post announces CVE‑2026‑28292 in simple‑git, warns of potential RCE, and urges users to promptly apply the vendor patch.

    0102065
    124 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    CVE-2026-28292: RCE in simple-git via case-sensitivity bypass (CVSS 9.8) https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292 https://t.co/LGG1EUPaFM

    Post summary

    A new high‑severity RCE vulnerability (CVE‑2026‑28292) in simple‑git has been disclosed via a case‑sensitivity bypass, with technical details and a link to a security research article.

    01020127
    594 followersView on X
  • Roma Keshkar@KeshkarRoma
    Disclosure

    @CVEnew this is the original research doc by @CodeAntAI - its found by our AI code reviewer https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292

    Post summary

    The tweet announces the original research document for CVE‑2026‑28292, indicating a remote code execution flaw, but does not provide any PoC, exploitation code, or patch information.

    0003042
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28292 `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two p… https://www.cve.org/CVERecord?id=CVE-2026-28292 ----- Traducción: CVE-2026-28292 `si… http://infoflow.cloud`

    Post summary

    CVE-2026-28292 is disclosed as affecting simple‑git versions 3.15.0–3.32.2, with a brief description of a bypass ability; no PoC, exploit, patch, or active exploitation details are provided.

    1002037
    57 followersView on X
  • Amartya Jha@amartya_jha_
    PoC

    @0dayPublishing If you want to see how we found this issue with the exploit and the PoC code, check this https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292

    Post summary

    The tweet shares a link to PoC code and an exploit for CVE‑2026‑28292, but does not mention active exploitation, patches, or technical details.

    10020159
    957 followersView on X
  • Amartya Jha@amartya_jha_
    Exploit

    Read the full exploit with the POC code and how we found this issue https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292

    Post summary

    The article announces a remote code execution flaw (CVE‑2026‑28292) in simple‑git, gives a full exploit and PoC code, but does not mention active attacks or a patch.

    00030170
    957 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsimple-git_projectsimple-git-node.js-

Explore more