CVE-2026-28291
Last modified
CVE-2026-28291 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as Git's flexible option parsing allows numerous character combinations (e.g., -vu, -4u, -nu) to circumvent the regular-expression-based blocklist in the unsafe operations plugin. Due to the virtually infinite number of valid option variants that Git accepts, a complete blocklist-based mitigation may be infeasible without fully emulating Git's option parsing behavior. This issue has been fixed in version 3.32.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Simple-Git Project | Simple-Git | < 3.32.0 |
References
- https://github.com/steveukx/git-js/security/advisories/GHSA-jcxm-m3jx-f287Exploit, Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-25860Third Party Advisory, VDB Entry
- https://github.com/steveukx/git-js/security/advisories/GHSA-jcxm-m3jx-f287Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-28291?
How severe is CVE-2026-28291?
How do I fix CVE-2026-28291?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-28282Discourse is an open-source discussion platform. Versions pr…6.5
- CVE-2026-28284FreePBX is an open source IP PBX. Prior to versions 16.0.10 …8.8
- CVE-2026-28286ZimaOS is a fork of CasaOS, an operating system for Zima dev…9.9
- CVE-2026-28287FreePBX is an open source IP PBX. From versions 16.0.17.2 to…8.8
- CVE-2026-28288Dify is an open-source LLM app development platform. Prior t…5.3
- CVE-2026-28289FreeScout is a free help desk and shared inbox built with PH…8.1
- CVE-2026-28292`simple-git`, an interface for running git commands in any n…9.8
- CVE-2026-28295A flaw was found in the FTP GVfs backend. A malicious FTP se…4.3
- CVE-2026-28296A flaw was found in the FTP GVfs backend. A remote attacker …4.3
- CVE-2026-28297SolarWinds Observability Self-Hosted was found to be affecte…8.7
- CVE-2026-28298SolarWinds Observability Self-Hosted was found to be affecte…8.1
- CVE-2026-28299SolarWinds Web Help Desk is found to be affected by a denial…7.5
Are you affected by CVE-2026-28291?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
