Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6951

Опубликовано: 25 апр. 2026
Источник: nvd
CVSS3: 9.8
CVSS3: 8.8
EPSS Низкий

Описание

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:*
Версия от 3.15.0 (включая) до 3.36.0 (исключая)

EPSS

Процентиль: 55%
0.00877
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-94
CWE-88

Связанные уязвимости

CVSS3: 8.8
redhat
3 месяца назад

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

CVSS3: 9.8
github
3 месяца назад

simple-git is vulnerable to Remote Code Execution

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость библиотеки simple-git программной платформы Node.js, позволяющая нарушителю изменить конфигурацию уязвимого программного обеспечения и выполнить произвольный код

EPSS

Процентиль: 55%
0.00877
Низкий

9.8 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-94
CWE-88