CVE-2026-28292
Critical · CVSS 9.8simple-git (git-js) — OS Command Injection / Case-sensitive bypass RCE (CWE-78, CWE-178, CWE-76)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-78, CWE-178, CWE-76
Description
`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability.
Search profile — drives PoC discovery
Symbols simple-gitgit-jssteveukxCleanOptionssanitizecheckIsReporemoteclonepullfetchGHSA-r275-fr43-pm7qf7042088aa2dac59e3c49a84d7a2f4b26048a257CVE-2022-25860CVE-2022-25912
Keywords CVE-2026-28292simple-git RCEsimple-git command injection bypassgit-js remote code executionGHSA-r275-fr43-pm7qsimple-git CVE-2022-25860 bypasssimple-git CVE-2022-25912 bypasssimple-git 3.15.0 3.32.2 exploitsimple-git sanitize bypassnode git command injection PoC
Versions: 3.15.0 through 3.32.2 (fixed in 3.23.0)
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/steveukx/git-js/commit/f7042088aa2dac59e3c49a84d7a2f4b26048a257
- https://github.com/steveukx/git-js/security/advisories/GHSA-r275-fr43-pm7q
- https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292
- https://access.redhat.com/security/cve/CVE-2026-28292
- https://bugzilla.redhat.com/show_bug.cgi?id=2446162
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28292.json
- https://www.codeant.ai/security-research/simple-git-remote-code-execution-cve-2026-28292
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z