CVE-2026-6951
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
वीकनेस
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
प्रभावित प्रोडक्ट
- simple-git_project simple-git
संदर्भ
- https://gist.github.com/KKC73/02d1d97f3410756095b501fda0ac8ca6
- https://github.com/steveukx/git-js/commit/89a2294febed5dfe737c4c735d936bb6018746a8
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16300211
- https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-15456078
- https://access.redhat.com/security/cve/CVE-2026-6951
- https://bugzilla.redhat.com/show_bug.cgi?id=2461750
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।