GitHub Security Advisories
2 h
GitHub Security Advisories
CVE-2026-102826: simple-git allows command execution through unblocked Git configuration includes
## Summary An OS command injection vulnerability in `git.clone()` allows any application that flows attacker-influenced data into `customArgs` to execute arbitrary code. simple-git 3.36.0 (current latest on npm) ships...