[npm] Remote code execution in simple-git #69

Open
opened 2026-08-06 12:12:03 +00:00 by victor · 0 comments
Member

Affected versions: < 3.16.0
Patched versions: 3.16.0

Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.

Affected versions: < 3.16.0 Patched versions: 3.16.0 Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.
victor added this to the v0.1.2 milestone 2026-08-06 12:12:03 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
MinBZK/DAWO-NixOS#69
No description provided.