Intel

AIKIDO-2026-566884

simple-git is vulnerable to Argument Injection

Argument InjectionGHSA-858h-whjf-mvg5 Published 2 days ago

81

High Risk

This Affects:

JSsimple-git
0.0.1 - 3.36.0
Fixed in 4.0.0
Are you affected? Scan for Free

TL;DR

simple-git blocks --upload-pack, --receive-pack, and --exec by matching the parsed flag name against a pattern that only covers the full spelling. Git accepts unambiguous prefix abbreviations of long options, but the parser never canonicalizes the flag name, so --receive-p=<command> or --exe=<command> passed through push or rebase gets past the check. Git still expands the abbreviation and runs the referenced program, so the injected command executes during the git operation. The fix extends the patterns to cover these abbreviated forms.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application passes externally influenced arguments to push or rebase.

Background info

simple-git is vulnerable to Argument Injection in versions 0.0.1 - 3.36.0.

How to fix this

Upgrade the simple-git library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform