All 5 CVE vulnerabilities found in git-js, with AI-generated Chinese analysis, references, and POCs.
Vendor: steveukx
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-102829 | simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection CWE-78 | 9.2 | Critical | 2026-09-29 |
| CVE-2026-102828 | simple-git unsafe-operation guard does not block trailer command configuration CWE-78 | 9.2 | Critical | 2026-09-29 |
| CVE-2026-102827 | simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291) CWE-77 | 8.1 | High | 2026-09-29 |
| CVE-2026-102826 | simple-git allows command execution through unblocked Git configuration includes CWE-77 | 8.1 | High | 2026-09-29 |
| CVE-2026-28291 | simple-git has Command Execution via Option-Parsing Bypass CWE-78 | 8.1 | High | 2026-04-13 |
All 5 known CVE vulnerabilities affecting git-js with full Chinese analysis, references, and POCs where available.