CVE-2026-6951
Critical · CVSS 9.8simple-git — Argument Injection / Remote Code Execution (RCE) via --config option bypass
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-94, CWE-88
Description
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
Search profile — drives PoC discovery
Symbols --config-cprotocol.ext.allow=alwaysext::optionsclonesimple-gitgit-jssteveukx
Keywords CVE-2026-6951simple-git RCEsimple-git --config bypasssimple-git argument injectionsimple-git ext:: cloneprotocol.ext.allowgit-js RCECVE-2022-25912 bypasssimple-git before 3.36.0SNYK-JS-SIMPLEGIT-15456078
Versions: <3.36.0
References
- https://gist.github.com/KKC73/02d1d97f3410756095b501fda0ac8ca6
- https://github.com/steveukx/git-js/commit/89a2294febed5dfe737c4c735d936bb6018746a8
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16300211
- https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-15456078
- https://access.redhat.com/security/cve/CVE-2026-6951
- https://bugzilla.redhat.com/show_bug.cgi?id=2461750
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6951.json
- https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-15456078
Status: enriched · ingested 2026-06-29T18:00:49.000Z · profiled 2026-07-01T18:30:14.000Z