Simple GIT interface for node.js
92%
Total Score
61
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-6951 simple-git is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.36.0. | 0.0.0 - 3.36.0 | Critical |
CVE-2026-28291 simple-git is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 3.32.0. | 0.0.0 - 3.32.0 | High |
AIKIDO-2026-10315 simple-git is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 3.32.1. | 0.0.1 - 3.32.1 | High |
CVE-2026-28292 simple-git is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 3.15.0 - 3.32.3. | 3.15.0 - 3.32.3 | Critical |
CVE-2022-25912 simple-git is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 0.0.0 - 3.15.0. | 0.0.0 - 3.15.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.4.0 | — | — |
@kwsites/file-exists Version ^1.1.1 | — | — |
@simple-git/argv-parser Version ^1.1.0 | — | — |
@kwsites/promise-deferred Version ^1.1.1 | — | — |
@simple-git/args-pathspec Version ^1.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant