CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-6951

Critical · CVSS 9.8

simple-git — Argument Injection / Remote Code Execution (RCE) via --config option bypass

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-94, CWE-88

Description

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

Search profile — drives PoC discovery

Symbols --config-cprotocol.ext.allow=alwaysext::optionsclonesimple-gitgit-jssteveukx
Keywords CVE-2026-6951simple-git RCEsimple-git --config bypasssimple-git argument injectionsimple-git ext:: cloneprotocol.ext.allowgit-js RCECVE-2022-25912 bypasssimple-git before 3.36.0SNYK-JS-SIMPLEGIT-15456078
Versions: <3.36.0

References

Status: enriched · ingested 2026-06-29T18:00:49.000Z · profiled 2026-07-01T18:30:14.000Z