VendorsSimple-git Projectsimple-gitall versions
Vulnerabilities

Simple-git Project Simple-git

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-24066
Command Injection
Published 2022-04-01 · Modified
9.8EPSS 0.039
CVE-2022-24433
Command Injection
Published 2022-03-11 · Modified
9.8EPSS 0.035
CVE-2022-25912
Remote Code Execution (RCE)
Published 2022-12-12 · Modified
9.8EPSS 0.029
CVE-2022-25860
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221).
Published 2023-01-24 · Modified
9.8EPSS 0.027
CVE-2026-28292
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE
Published 2026-03-10 · Modified
9.8EPSS 0.013
CVE-2026-6951
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Published 2026-04-25 · Modified
9.8EPSS 0.010
CVE-2026-28291
simple-git has Command Execution via Option-Parsing Bypass
Published 2026-04-13 · Modified
8.1EPSS 0.009