GHSA-x6jw-m9v5-85vh: OS Command Injection

Published Oct 5, 2026
·
Updated

Affected product

The default blockUnsafeOperationsPlugin in simple-git when an application permits untrusted values to reach SimpleGitOptions.config or Git inline configuration arguments such as -c <key>=<value>.

Summary

trailer.<token>.cmd is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a GitPluginError.

Git documents trailer.<token>.cmd as a shell command invoked by git interpret-trailers. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.

Technical details

simple-git/src/lib/git-factory.ts installs commandConfigPrefixingPlugin before blockUnsafeOperationsPlugin. The prefixing plugin in simple-git/src/lib/plugins/command-config-prefixing-plugin.ts turns every SimpleGitOptions.config entry into -c <key>=<value> before the unsafe-operation plugin evaluates the final argv.

In simple-git@3.36.0, blockUnsafeOperationsPlugin delegates to @simple-git/argv-parser. packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts compares parsed configuration writes against preventUnsafeConfig. That list has no matcher for trailer.<token>.cmd, so the invocation is allowed.

Git v2.39.5's Documentation/git-interpret-trailers.txt states that trailer.<token>.cmd specifies a shell command called to generate or modify a trailer.

Preconditions

The application must use an affected simple-git version with the default unsafe-operation plugin active and must pass attacker-controlled data into instance configuration or Git command arguments that configure trailer.<token>.cmd.

The invoked Git binary must support the documented trailer-command behavior, and the application must execute git interpret-trailers with the attacker-controlled configuration in scope. The command runs with the operating-system identity and permissions of the Node.js process.

Verification

Use an isolated test environment and a harmless executable test helper that records only its invocation.

Control: Configure core.editor=<test-helper> through SimpleGitOptions.config and invoke a benign Git task. The default plugin should throw GitPluginError before spawning Git because core.editor is present in preventUnsafeConfig.

Bypass: Configure trailer.audit.cmd=<test-helper> through the same option and invoke Git with the equivalent argv shape:

git -c trailer.audit.cmd=<test-helper> interpret-trailers --trailer audit:<value> <input-file>

A vulnerable build does not raise GitPluginError; Git invokes the test helper while processing the trailer. Confirm the helper invocation, then remove test artifacts.

Impact

An attacker who controls the stated configuration input can cause Git to execute a shell command as the Node.js application process. The impact is bounded by that process's filesystem, network, and service permissions. Applications that do not expose untrusted configuration or command arguments to simple-git are outside this threat model.

Affected versions

Commit 6b3c631eadea81f80ed10f6dec7d19a9db4d7084 introduced the default unsafe-operation plugin, and simple-git@3.15.0 is the first release confirmed to contain it. Its implementation only rejected protocol.allow configuration, leaving trailer-command configuration unblocked.

The latest simple-git release, 3.36.0, still lacks a trailer-command matcher. The current main branch also lacks one. No released remediation was identified.

Remediation

Default-deny configuration keys that can trigger executable behavior, or add a dedicated unsafe category that rejects trailer.<token>.cmd before spawning Git unless the application explicitly opts in.

Evaluate trailer.<token>.command alongside .cmd, because Git documents it as related command behavior. Add parser and integration tests for leading -c, configured instance prefixes, and git config write forms, asserting that no Git child process is spawned without an explicit unsafe opt-in.

Evidence

- simple-git@3.15.0 was released on 2022-11-12 and contains the initial unsafe-operation plugin. - simple-git@3.36.0 was released on 2026-04-12; its parser source does not match trailer.<token>.cmd. - main retains the missing matcher in packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts. - Git v2.39.5 documents the trailer command behavior in Documentation/git-interpret-trailers.txt. - PR #1167 expanded other configuration checks but did not add a trailer-command matcher and is not release-backed as a remediation. - This review verified repository, release, and source artifacts through GitHub; it did not independently execute the runtime reproduction.

Affected Software

1 affected componentFixes available
npm/simple-git>=3.15.0<4.0.1
4.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/simple-git to a version that resolves this vulnerability.

    Fixed in 4.0.1
  2. Compensating control

    Default-deny executable Git configuration keys before spawning Git, including trailer.<token>.cmd and trailer.<token>.command; reject these values unless the application explicitly opts in.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:48 PM
Data Sourced
via GitHub·11:48 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications are exposed when untrusted values can reach SimpleGitOptions.config or Git inline configuration arguments such as -c <key>=<value>. Applications that do not allow untrusted input into those configuration paths are not described as affected.

2

What does an attacker need to control to trigger command execution?

An attacker needs to supply a trailer.<token>.cmd configuration value through an untrusted SimpleGitOptions.config entry or inline Git configuration argument. The configured command is invoked by git interpret-trailers.

3

Does simple-git's default unsafe-operation protection block this configuration?

No. The default blockUnsafeOperationsPlugin does not recognize trailer.<token>.cmd as unsafe, so the value can reach Git without producing a GitPluginError.

4

How can I determine whether my integration is at risk?

Review whether user-controlled or otherwise untrusted input is passed into SimpleGitOptions.config or into -c configuration arguments. In particular, identify whether an input can set a key matching trailer.<token>.cmd and whether your workflow invokes git interpret-trailers.

5

What can be done while patching is not available?

Do not allow untrusted values to populate SimpleGitOptions.config or inline Git configuration arguments. At minimum, prevent untrusted configuration keys or values from creating trailer.<token>.cmd settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203