CVE-2026-6951: Code Injection
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
simple-gitto a version that resolves this vulnerability.Fixed in 3.36.0 - Configuration
Do not allow untrusted users to enable/propagate `protocol.ext.allow=always` into the `options` argument passed to simple-git; prevent untrusted input from controlling this setting.
simple-git (git configuration via options argument) protocol.ext.allow = always - Compensating control
Ensure untrusted input cannot reach the `options` argument passed to simple-git (e.g., validate/whitelist and reject attacker-controlled option values such as `--config` that could enable `protocol.ext.allow=always`).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6951?
CVE-2026-6951 has a critical severity rating due to its potential for remote code execution.
How do I fix CVE-2026-6951?
To resolve CVE-2026-6951, upgrade to simple-git version 3.36.0 or later.
What types of attacks can CVE-2026-6951 enable?
CVE-2026-6951 can enable attackers to execute arbitrary code on the affected system.
Which versions of simple-git are affected by CVE-2026-6951?
CVE-2026-6951 affects all versions of simple-git prior to 3.36.0.
Is there a workaround for CVE-2026-6951?
No known workaround exists for CVE-2026-6951, so upgrading is the recommended solution.