CyberRota
Back to database

CVE-2026-6951

CRITICAL · CVSS 9.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-04-25 · Last synced: 2026-05-25

CyberRota Analysis

Uzaktan istismar edilebilir olabilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-6951
Severity
CRITICAL
CVSS
9.8
EPSS
0.14%

Original NVD Description

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.