{"id":"GHSA-hffm-xvc3-vprc","summary":"simple-git is vulnerable to Remote Code Execution","details":"Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.","aliases":["CVE-2026-6951"],"modified":"2026-07-17T21:12:06.509100119Z","published":"2026-04-25T06:30:23Z","database_specific":{"github_reviewed_at":"2026-05-05T20:12:16Z","nvd_published_at":"2026-04-25T06:16:16Z","cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6951"},{"type":"WEB","url":"https://github.com/steveukx/git-js/commit/89a2294febed5dfe737c4c735d936bb6018746a8"},{"type":"WEB","url":"https://gist.github.com/KKC73/02d1d97f3410756095b501fda0ac8ca6"},{"type":"PACKAGE","url":"https://github.com/steveukx/git-js"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-15456078"}],"affected":[{"package":{"name":"simple-git","ecosystem":"npm","purl":"pkg:npm/simple-git"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.36.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-hffm-xvc3-vprc/GHSA-hffm-xvc3-vprc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}