Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simple Git CRITICAL 9.8
CVE-2026-6951

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://…

Fix: 3.36.0+
Fix from $2,300 2026-04-25
Simple Git HIGH 8.1
CVE-2026-28291

simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git…

Fix: 3.32.0+
Fix from $1,950 2026-04-13
Simple Git CRITICAL 9.8
CVE-2026-28292

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacke…

Fix: 3.32.2+
Fix from $2,300 2026-03-10
Simple Git CRITICAL 9.8
CVE-2022-25860

Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() metho…

Fix: 3.16.0+
Fix from $2,300 2023-01-26
Simple Git CRITICAL 9.8
CVE-2022-25912

The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitab…

Fix: 3.15.0+
Fix from $2,300 2022-12-06
Simple Git CRITICAL 9.8
CVE-2022-24066

The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SN…

Fix: 3.5.0+
Fix from $2,300 2022-04-01
Simple Git CRITICAL 9.8
CVE-2022-24433

The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) fu…

Fix: 3.3.0+
Fix from $2,300 2022-03-11