CVE-2026-28291 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: April 14, 2026
simple-git - Command Injection
Overview
simple-git <= 3.31.1 contains a command injection caused by incomplete blocklist of Git options in unsafe operations plugin, letting attackers execute arbitrary commands by manipulating Git options, exploit requires crafted Git command options.
Severity & Score
Impact
Attackers can execute arbitrary commands, potentially leading to full system compromise.
Mitigation
Update to version 3.32.0 or later.
References
- https://github.com/steveukx/git-js/releases/tag/simple-git%403.32.0
- https://github.com/steveukx/git-js/security/advisories/GHSA-jcxm-m3jx-f287
- https://www.cve.org/CVERecord?id=CVE-2022-25860
- https://github.com/steveukx/git-js/commit/1effd8e5012a5da05a9776512fac3e39b11f2d2d
- https://github.com/steveukx/git-js/blob/789c13ebabcf18ebe0b3a0c88ebb4037dede42e3/simple-git/src/lib/plugins/block-unsafe-operations-plugin.ts#L26
Social Media Activity(2 posts)
š CVE-2026-28291 - High (8.1) simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --uploa... š https://www.thehackerwire.com/vulnerability/CVE-2026-28291/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-28291 - High (8.1) simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --uploa... š https://www.thehackerwire.com/vulnerability/CVE-2026-28291/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-28291
- Severity
- High
- CVSS Score
- 8.1
- Type
- command_injection
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H