simple-git project records
7 published records for vendor simple-git project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-24066No exploit | The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.isimple-git project · simple-git · CWE-88 | Critical9.8 | — | 3.9% | Apr 1, 2022 |
40Plan | CVE-2022-24433No exploit | The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection.simple-git project · simple-git · CWE-88 | Critical9.8 | — | 3.5% | Mar 11, 2022 |
40Plan | CVE-2022-25912No exploit | Remote Code Execution (RCE)simple-git project · simple-git · CWE-78 | Critical9.8 | — | 2.9% | Dec 6, 2022 |
40Plan | CVE-2022-25860No exploit | Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemotsimple-git project · simple-git · CWE-94 | Critical9.8 | — | 2.7% | Jan 26, 2023 |
39Monitor | CVE-2026-28292No exploit | simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCEsimple-git project · simple-git · CWE-78 | Critical9.8 | — | 1.3% | Mar 10, 2026 |
32Monitor | CVE-2026-6951Proof of concept | Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912]simple-git project · simple-git · CWE-94 | High8.2 | — | 1.0% | Apr 25, 2026 |
32Monitor | CVE-2026-28291No exploit | simple-git has Command Execution via Option-Parsing Bypasssimple-git project · simple-git · CWE-78 | High8.1 | — | 0.9% | Apr 13, 2026 |
- CVE-2022-2406640Plan
The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.i
CriticalCVSS 9.8No exploitEPSS 4%simple-git project · simple-gitApr 1, 2022
- CVE-2022-2443340Plan
The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection.
CriticalCVSS 9.8No exploitEPSS 4%simple-git project · simple-gitMar 11, 2022
- CVE-2022-2591240Plan
Remote Code Execution (RCE)
CriticalCVSS 9.8No exploitEPSS 3%simple-git project · simple-gitDec 6, 2022
- CVE-2022-2586040Plan
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemot
CriticalCVSS 9.8No exploitEPSS 3%simple-git project · simple-gitJan 26, 2023
- CVE-2026-2829239Monitor
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE
CriticalCVSS 9.8No exploitEPSS 1%simple-git project · simple-gitMar 10, 2026
- CVE-2026-695132Monitor
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912]
HighCVSS 8.2Proof of conceptEPSS 1%simple-git project · simple-gitApr 25, 2026
- CVE-2026-2829132Monitor
simple-git has Command Execution via Option-Parsing Bypass
HighCVSS 8.1No exploitEPSS 1%simple-git project · simple-gitApr 13, 2026