Skip to main content

Vendor/product archive

simple-git_project / simple-git CVEs

Beta · best-effort

7 CVEs tagged to simple-git_project / simple-git1 Critical, 6 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-6951

Published Apr 25, 2026

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-…

CVSS 8.2 · High
evidence mentions
7
Buzz score
36.8
Vendor/product tagsBeta · best-effort

CVE-2026-28291

Published Apr 13, 2026

simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassin…

CVSS 8.1 · High
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2026-28292

Published Mar 10, 2026

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixe…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
41.5
Vendor/product tagsBeta · best-effort

CVE-2022-25860

Published Jan 26, 2023

Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sani…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-25912

Published Dec 6, 2022

The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vu…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24066

Published Apr 1, 2022

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24433

Published Mar 11, 2022

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and br…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1