« Back to list

Simple-git

Simple-git: vulnerabilities and CVEs

Simple-git has 4 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-102829Critical (9.2)0.27%—Sep 29, 2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from…
CVE-2026-102828Critical (9.2)0.27%—Sep 29, 2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not…
CVE-2026-102827High (8.1)0.36%—Sep 29, 2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed…
CVE-2026-102826High (8.1)0.46%—Sep 29, 2026
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1059 Command and Scripting Interpreter3
  3. T1059.001 PowerShell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Simple-git