CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-28292

Critical · CVSS 9.8

simple-git (git-js) — OS Command Injection / Case-sensitive bypass RCE (CWE-78, CWE-178, CWE-76)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-78, CWE-178, CWE-76

Description

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability.

Search profile — drives PoC discovery

Symbols simple-gitgit-jssteveukxCleanOptionssanitizecheckIsReporemoteclonepullfetchGHSA-r275-fr43-pm7qf7042088aa2dac59e3c49a84d7a2f4b26048a257CVE-2022-25860CVE-2022-25912
Keywords CVE-2026-28292simple-git RCEsimple-git command injection bypassgit-js remote code executionGHSA-r275-fr43-pm7qsimple-git CVE-2022-25860 bypasssimple-git CVE-2022-25912 bypasssimple-git 3.15.0 3.32.2 exploitsimple-git sanitize bypassnode git command injection PoC
Versions: 3.15.0 through 3.32.2 (fixed in 3.23.0)

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z