Junglewise Threat Intelligence

CVE-2022-25912: simple-git remote code execution via ext transport protocol

CVE-2022-25912 · Severity: low · CVSS 3.1 · Published 2022-12-06

Technologies: simple-git (npm). Vendors: npm.

Executive brief

simple-git is a popular Node.js library for interacting with Git repositories. When the ext transport protocol is enabled, attackers can execute arbitrary code on the host system via the clone() method. This is a re-introduction of a previously patched vulnerability and could allow attackers to compromise applications that use simple-git without proper safeguards.

Technical details

The vulnerability is an incomplete fix of CVE-2022-24066 involving OS command injection (CWE-78) in the Git transport handling mechanism. When the ext transport protocol is enabled (via the allowUnsafeProtocolOverride configuration option), the clone() method does not properly sanitize user-controlled repository URLs before passing them to shell execution. An attacker can craft a malicious repository URL containing shell metacharacters to execute arbitrary commands with the privileges of the application. The vulnerability requires the developer to explicitly enable unsafe protocol overrides, but this configuration may be enabled unknowingly or intentionally for compatibility. The fix was released in version 3.15.0.

Affected products

  • simple-git simple-git < 3.15.0

Timeline

  • 2022-12-06: disclosed
  • 2022-11-12: patched: Fix released in version 3.15.0

References

Related threats