git-js vulnerabilities
CVEs whose affected-version data names the git-js package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-102829Critical· 9.2PoCsimple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv…
CVE-2026-102828Critical· 9.2simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<tok…
CVE-2026-102827High· 8.1simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with liter…
CVE-2026-102826High· 8.1PoCsimple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuratio…