OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102827

HIGH · CVSS 8.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the simple-git interface in Java applications, allowing attackers to exploit improperly validated Git command options, potentially leading to unauthorized command execution. This could enable an attacker to manipulate Git operations, posing significant risks to applications that rely on this library for version control. Developers using versions prior to 4.0.0 should prioritize upgrading to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102827
Severity
HIGH
CVSS
8.1
EPSS
0.36%
Java

Original NVD Description

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.