Executive brief
simple-git is a popular library used by developers to run Git commands within JavaScript applications. A security flaw allows attackers to bypass safety filters and execute unauthorized system commands by disguising dangerous Git options. This could lead to full system compromise or unauthorized data access if an application passes untrusted user input to the library.
Technical details
A command injection vulnerability exists in simple-git due to an incomplete fix for CVE-2022-25860. The library's 'unsafe operations' plugin uses a regular-expression-based blocklist to prevent dangerous Git flags (like --upload-pack or -u in clone operations) that can trigger arbitrary command execution. However, Git's flexible option parsing allows attackers to combine flags (e.g., -vu, -4u) or use specific character sequences that circumvent these regex checks. An attacker who can control the arguments passed to Git methods can achieve arbitrary code execution on the host system. The issue is addressed in version 3.32.0 by enhancing the option-blocking logic.
Affected products
- steveukx simple-git <= 3.31.1
Timeline
- 2026-02-21: patched: Fix committed and version 3.32.0 released
- 2026-04-12: advisory: GitHub Security Advisory GHSA-jcxm-m3jx-f287 published
- 2026-04-13: disclosed: CVE-2026-28291 published to NVD
References
- https://github.com/steveukx/git-js/blob/789c13ebabcf18ebe0b3a0c88ebb4037dede42e3/simple-git/src/lib/plugins/block-unsafe-operations-plugin.ts
- https://github.com/steveukx/git-js/commit/1effd8e5012a5da05a9776512fac3e39b11f2d2d
- https://github.com/steveukx/git-js/releases/tag/simple-git%403.32.0
- https://github.com/steveukx/git-js/security/advisories/GHSA-jcxm-m3jx-f287
- https://www.cve.org/CVERecord?id=CVE-2022-25860
- https://access.redhat.com/security/cve/CVE-2026-28291
- https://bugzilla.redhat.com/show_bug.cgi?id=2457930