Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hffm-xvc3-vprc

Опубликовано: 25 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 9.8

Описание

simple-git is vulnerable to Remote Code Execution

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

Пакеты

Наименование

simple-git

npm
Затронутые версииВерсия исправления

< 3.36.0

3.36.0

EPSS

Процентиль: 55%
0.00877
Низкий

8.2 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
redhat
3 месяца назад

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

CVSS3: 9.8
nvd
3 месяца назад

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость библиотеки simple-git программной платформы Node.js, позволяющая нарушителю изменить конфигурацию уязвимого программного обеспечения и выполнить произвольный код

EPSS

Процентиль: 55%
0.00877
Низкий

8.2 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94