GHSA-858h-whjf-mvg5: Command Injection

Published Oct 5, 2026
·
Updated

simple-git's blockUnsafeOperationsPlugin blocks dangerous git options (--upload-pack/--receive-pack/--exec/...) unless the consumer opts in via unsafe:{allowUnsafePack:true}. Detection (@simple-git/argv-parser detectVulnerableFlags) matches the parsed flag NAME against literal-spelling patterns: /--(upload|receive)-pack/ (requires the literal '-pack') and the string '--exec'. But git accepts unambiguous prefix abbreviations of long options, and expandToken (token-expander.ts) returns the LITERAL token as flag.name (it uses the spec only for needsNext, never to canonicalize). So git push --receive-p=<cmd> parses with flag.name='--receive-p', which /--(upload|receive)-pack/ does NOT match, yet git expands --receive-p -> --receive-pack and runs <cmd> (on a local/file remote, locally). The clone side is robust (its '--u' substring rule catches every --upload abbreviation); the push --receive- and --exe abbreviations have no equivalent rule and slip through.

Proof of concept (latest: simple-git 3.36.0, @simple-git/argv-parser 1.1.1, default unsafe plugin ON): Gate vulnerabilityCheck: 'push --receive-pack=touch...' -> BLOCKED; 'push --receive-pa=touch...' and 'push --receive-p=touch...' -> BYPASS (empty vulns); '--exec=' BLOCKED, '--exe=' BYPASS. End-to-end via simpleGit().push(): CONTROL git.push(['../bare','HEAD:refs/heads/c','--receive-pack=touch /tmp/pwnedctrl;']) -> throws GitPluginError 'Use of --upload-pack or --receive-pack is not permitted...'; no command runs. BYPASS git.push(['../bare','HEAD:refs/heads/e2e','--receive-p=touch /tmp/pwnede2e;']) -> NO GitPluginError; /tmp/pwnede2e CREATED (git executed the injected command); only a later GitError surfaces. Direct git confirms git push ../bare --receive-p='touch X;' HEAD:refs/heads/m and --exe='touch Y;' both execute on a local/path remote.

Impact: any app relying on simple-git's default unsafe-operations protection while passing attacker-influenced options/args into a git push (local/file remote, or attacker-influenced receive-pack target) can be made to execute arbitrary commands -- the exact protection CVE-2026-28291 provided, defeated by an abbreviated spelling. Same class/impact as GHSA-jcxm-m3jx-f287, on the push path.

Remediation: canonicalize git option abbreviations before matching (resolve to the canonical long name via the per-task flag spec in expandToken), or match on the option stem/prefix down to the shortest unambiguous form for push receive-pack/exec (mirroring the clone-side '--u' approach). Also audit --template and -c/config-write detection for the same abbreviation gap.

Credit: anir0y (independent security research).

Affected Software

1 affected componentFixes available
npm/simple-git<=3.36.0
4.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/simple-git to a version that resolves this vulnerability.

    Fixed in 4.0.0
  2. Compensating control

    Update simple-git's unsafe-operation detection to canonicalize abbreviated Git options before matching, resolving each token through the per-task flag specification in expandToken, so abbreviations such as --receive-p, --receive-pa, and --exe are detected as --receive-pack and --exec; also audit --template and -c/config-write detection for the same abbreviation gap.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:47 PM
Data Sourced
via GitHub·11:47 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Is the default safety configuration affected?

Yes. The proof of concept states that the default unsafe plugin is enabled, but abbreviated push options such as --receive-pa and --receive-p bypass its literal-option matching.

2

What conditions are needed for exploitation?

An attacker needs to influence arguments passed to a simple-git push operation so that an abbreviated --receive-pack or --exec option is used. For the demonstrated --receive-pack path, a local or file remote can cause the supplied command to run locally.

3

Which operations are affected by this detection gap?

The described gap affects push-side abbreviations of --receive-pack and --exec. Clone-side --upload-pack abbreviations are described as being caught by the existing --u substring rule.

4

How can I identify potentially affected usage?

Review application paths that construct simple-git push commands from untrusted or externally controlled input, especially inputs that can introduce abbreviated long options such as --receive-p or --exe. The vulnerable parser preserves the abbreviated token as the flag name rather than canonicalizing it before safety checks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203