Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r275-fr43-pm7q | simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE |
Tue, 14 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Mon, 13 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE | simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE |
| References |
|
Fri, 13 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-76 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 12 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simple-git Project
Simple-git Project simple-git |
|
| CPEs | cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Simple-git Project
Simple-git Project simple-git |
Wed, 11 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steveukx
Steveukx simple-git |
|
| Vendors & Products |
Steveukx
Steveukx simple-git |
Tue, 10 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability. | |
| Title | simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE | |
| Weaknesses | CWE-178 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-14T15:30:40.620Z
Reserved: 2026-02-26T01:52:58.736Z
Link: CVE-2026-28292
Updated: 2026-03-11T14:16:25.324Z
Status : Modified
Published: 2026-03-10T19:17:20.840
Modified: 2026-04-14T16:16:38.047
Link: CVE-2026-28292
OpenCVE Enrichment
Updated: 2026-04-15T17:00:07Z
Github GHSA