CVE-2026-102828Critical· 9.2▾ Midnightsimple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<tok…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102829Critical· 9.2simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
CVE-2026-102826High· 8.1simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
CVE-2026-102827High· 8.1simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
CVE-2026-87911Critical· 9.6An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…
CVE-2025-9580Medium· 6.3A security vulnerability has been detected in LB-LINK BL-X26 1.2.8
CVE-2025-9579Medium· 6.3A weakness has been identified in LB-LINK BL-X26 1.2.8