Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jcxm-m3jx-f287 | simple-git Affected by Command Execution via Option-Parsing Bypass |
Wed, 13 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simple-git Project
Simple-git Project simple-git |
|
| CPEs | cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Simple-git Project
Simple-git Project simple-git |
Tue, 14 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steveukx
Steveukx git-js |
|
| Vendors & Products |
Steveukx
Steveukx git-js |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 13 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as Git's flexible option parsing allows numerous character combinations (e.g., -vu, -4u, -nu) to circumvent the regular-expression-based blocklist in the unsafe operations plugin. Due to the virtually infinite number of valid option variants that Git accepts, a complete blocklist-based mitigation may be infeasible without fully emulating Git's option parsing behavior. This issue has been fixed in version 3.32.0. | |
| Title | simple-git has Command Execution via Option-Parsing Bypass | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-14T16:30:34.266Z
Reserved: 2026-02-26T01:52:58.735Z
Link: CVE-2026-28291
Updated: 2026-04-14T13:53:28.645Z
Status : Analyzed
Published: 2026-04-13T18:16:28.760
Modified: 2026-05-13T20:52:38.827
Link: CVE-2026-28291
OpenCVE Enrichment
Updated: 2026-04-14T16:33:50Z
Github GHSA