OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102828

CRITICAL · CVSS 9.2 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects the simple-git interface used in Node.js applications, specifically versions 3.15.0 to 4.0.1, where the default configuration fails to classify certain commands as unsafe. This oversight allows an attacker to execute arbitrary shell commands with the same permissions as the Node.js process, posing a critical security risk. Organizations utilizing affected versions should prioritize immediate upgrades to version 4.0.1 to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102828
Severity
CRITICAL
CVSS
9.2
EPSS
0.27%
Java

Original NVD Description

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.