Simple-git Project
Simple-git Project Simple-git: vulnerabilities and CVEs
Simple-git Project Simple-git has 7 published vulnerabilities, 3 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months3
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6951 | High (8.2) | 1.0% | — | Apr 25, 2026 | Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c… |
| CVE-2026-28291 | High (8.1) | 0.93% | — | Apr 13, 2026 | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous… |
| CVE-2026-28292 | Critical (9.8) | 1.3% | — | Mar 10, 2026 | `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912)… |
| CVE-2022-25860 | Critical (9.8) | 2.7% | — | Jan 26, 2023 | Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due… |
| CVE-2022-25912 | Critical (9.8) | 2.9% | — | Dec 6, 2022 | The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete… |
| CVE-2022-24066 | Critical (9.8) | 3.9% | — | Apr 1, 2022 | The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch… |
| CVE-2022-24433 | Critical (9.8) | 3.5% | — | Mar 11, 2022 | The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git… |