simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe confi
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102829 | 9.2 CRITICAL | simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection |
| CVE-2026-102826 | 8.1 HIGH | simple-git allows command execution through unblocked Git configuration includes |
| CVE-2026-102827 | 8.1 HIGH | simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/ |
No comments yet