Intel

AIKIDO-2026-378256

simple-git is vulnerable to Command Injection

Command InjectionGHSA-x6jw-m9v5-85vh Published 2 days ago

81

High Risk

This Affects:

JSsimple-git
3.15.0 - 3.36.0
Fixed in 4.0.0
Are you affected? Scan for Free

TL;DR

simple-git has an unsafe operation guard that rejects a fixed list of dangerous Git configuration keys before they reach the git child process, but the list omitted trailer.cmd and trailer.command. Git runs both keys as a shell command in git interpret-trailers, so a value set through SimpleGitOptions.config or an inline -c argument under either key reached git with no guard in place. An application that passes untrusted input into instance configuration can have an arbitrary shell command run during a git operation. The fix adds matchers for both keys to the guard's denylist.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application passes externally influenced values into SimpleGitOptions.config or an inline -c argument.

Background info

simple-git is vulnerable to Command Injection in versions 3.15.0 - 3.36.0.

How to fix this

Upgrade the simple-git library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform