CVE-2026-102826: simple-git allows command execution through unblocked Git configuration includes

Published Sep 29, 2026
·
Updated

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf.<condition>.path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0.

Affected Software

1 affected component
npm/simple-git<4.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade simple-git to a version that resolves this vulnerability.

    Fixed in 4.0.0

Event History

Sep 29, 2026
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed?

Applications using simple-git before 4.0.0 are exposed only where attacker-influenced values can be passed as customArgs to git.clone() and the Node.js process can read an attacker-controlled Git configuration file.

2

What does an attacker need to exploit this?

The attacker needs to influence custom arguments supplied to git.clone() and arrange for Git to load a configuration file under their control that is readable by the application process. They can use include.path or a conditional includeIf.<condition>.path to load that file.

3

What is the impact after a malicious configuration is loaded?

The configuration can set an executable Git option such as core.sshCommand. Git invokes that command during cloning with the privileges of the Node.js process, allowing command execution with high confidentiality, integrity, and availability impact.

4

What should be done if upgrading is not immediately possible?

Do not pass attacker-influenced customArgs to git.clone(), and prevent the application process from reading attacker-controlled Git configuration files. Pay particular attention to arguments that can introduce include.path or includeIf.<condition>.path configuration includes.

5

How is the issue fixed?

Upgrade simple-git to version 4.0.0, which fixes the incomplete rejection of configuration includes in custom arguments to git.clone().

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203