CVE-2026-102828: simple-git unsafe-operation guard does not block trailer command configuration
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
simple-gitto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Frequently Asked Questions
Which applications are realistically exposed?
Applications using simple-git from 3.15.0 through versions before 4.0.1 are exposed if they pass attacker-controlled values through SimpleGitOptions.config or inline Git -c arguments and later invoke git interpret-trailers with the configured trailer.
What does an attacker need to exploit this issue?
The attacker needs influence over a Git configuration key or inline -c argument accepted by the application, specifically a trailer.<token>.cmd setting, and a path that causes git interpret-trailers to process that trailer configuration. The resulting command runs with the operating-system identity and permissions of the Node.js process.
Are default simple-git protections sufficient?
No. In affected versions, the default blockUnsafeOperationsPlugin does not treat trailer.<token>.cmd as unsafe, so its default unsafe-operation guard does not block this configuration.
What is the available remediation?
Upgrade simple-git to version 4.0.1, which fixes the issue. Until then, do not pass untrusted input through SimpleGitOptions.config or inline -c arguments, particularly configuration keys matching trailer.<token>.cmd.