Skip to content
Noroxi

simple-git project records

7 published records for vendor simple-git project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

7 records
  • The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.i

    CriticalCVSS 9.8No exploitEPSS 4%

    simple-git project · simple-gitApr 1, 2022

  • The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection.

    CriticalCVSS 9.8No exploitEPSS 4%

    simple-git project · simple-gitMar 11, 2022

  • Remote Code Execution (RCE)

    CriticalCVSS 9.8No exploitEPSS 3%

    simple-git project · simple-gitDec 6, 2022

  • Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemot

    CriticalCVSS 9.8No exploitEPSS 3%

    simple-git project · simple-gitJan 26, 2023

  • simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE

    CriticalCVSS 9.8No exploitEPSS 1%

    simple-git project · simple-gitMar 10, 2026

  • CVE-2026-6951
    32Monitor

    Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912]

    HighCVSS 8.2Proof of conceptEPSS 1%

    simple-git project · simple-gitApr 25, 2026

  • simple-git has Command Execution via Option-Parsing Bypass

    HighCVSS 8.1No exploitEPSS 1%

    simple-git project · simple-gitApr 13, 2026