CVE-2026-102826: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in steveukx git-js
CVE-2026-102826 is a command injection vulnerability in the simple-git interface (git-js) for Node.js applications. Versions prior to 4.0.0 do not fully block unsafe operations when using custom arguments in git.clone(), allowing attacker-controlled configuration files to be loaded. This can lead to execution of arbitrary commands with the privileges of the Node.js process. The issue is fixed in version 4.0.0.
AI Analysis
Technical Summary
The vulnerability exists because simple-git versions before 4.0.0 do not completely reject configuration includes supplied via customArgs to git.clone(). Specifically, the default blockUnsafeOperationsPlugin misses include.path and includeIf.<condition>.path, enabling an attacker to load a malicious Git configuration file. This configuration can set executable Git options like core.sshCommand, which Git executes during cloning with Node.js process privileges. Exploitation requires the application to accept attacker-controlled custom arguments and an attacker-controlled file readable by the process. The vulnerability is addressed in version 4.0.0.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the Node.js process running the simple-git interface. This can lead to full compromise of the affected system, including confidentiality, integrity, and availability impacts.
Mitigation Recommendations
Upgrade to simple-git version 4.0.0 or later, where this vulnerability is fixed. Prior versions are vulnerable. No other mitigations are indicated in the advisory.
CVE-2026-102826: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in steveukx git-js
Description
CVE-2026-102826 is a command injection vulnerability in the simple-git interface (git-js) for Node.js applications. Versions prior to 4.0.0 do not fully block unsafe operations when using custom arguments in git.clone(), allowing attacker-controlled configuration files to be loaded. This can lead to execution of arbitrary commands with the privileges of the Node.js process. The issue is fixed in version 4.0.0.
CVSS v3.1
Score 8.1high
Affected software
steveukx
git-js
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists because simple-git versions before 4.0.0 do not completely reject configuration includes supplied via customArgs to git.clone(). Specifically, the default blockUnsafeOperationsPlugin misses include.path and includeIf.<condition>.path, enabling an attacker to load a malicious Git configuration file. This configuration can set executable Git options like core.sshCommand, which Git executes during cloning with Node.js process privileges. Exploitation requires the application to accept attacker-controlled custom arguments and an attacker-controlled file readable by the process. The vulnerability is addressed in version 4.0.0.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary commands with the privileges of the Node.js process running the simple-git interface. This can lead to full compromise of the affected system, including confidentiality, integrity, and availability impacts.
Mitigation Recommendations
Upgrade to simple-git version 4.0.0 or later, where this vulnerability is fixed. Prior versions are vulnerable. No other mitigations are indicated in the advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-29T17:25:25.265Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc08c9680226ef682285c7
Added to database: 09/29/2026, 18:51:53 UTC
Last enriched: 09/29/2026, 19:06:21 UTC
Last updated: 09/29/2026, 19:06:21 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.