Skip to content
Threat Feed
high threat exploited

Remote Code Execution via simple-git trailer.cmd Configuration

The simple-git library fails to block 'trailer.<token>.cmd' configuration in its unsafe-operation guard, enabling command injection when applications process untrusted user input.

CVE search metadata

CVE search record: CVE-2026-102828. EPSS: 0.27%. KEV: no. Product: simple-git (3.15.0 - 4.0.0). Brief: Remote Code Execution via simple-git trailer.cmd Configuration. Brief link: https://feed.craftedsignal.io/briefs/2026-10-simple-git-vulnerability/

The simple-git library (versions 3.15.0 through 3.36.0) contains a vulnerability in its blockUnsafeOperationsPlugin that fails to classify trailer.<token>.cmd as a dangerous Git configuration option. Git supports trailer commands to dynamically generate or modify metadata during operations like git interpret-trailers. Because simple-git does not include this key in its preventUnsafeConfig blocklist, an application that allows untrusted user input to influence Git configuration (e.g., via SimpleGitOptions.config or inline -c arguments) can be coerced into executing arbitrary shell commands. When the git binary is invoked with these attacker-controlled trailers, it executes the specified command with the permissions and environment of the Node.js process. This affects applications that bridge user-supplied data to simple-git configuration parameters without strict validation.

Attack Chain

  1. Attacker identifies an application endpoint or input field that passes user-controlled strings into simple-git configuration parameters.
  2. Attacker crafts a malicious configuration payload: trailer.exploit.cmd=<malicious_command>.
  3. The Node.js application accepts the input and initializes simple-git with the tainted configuration.
  4. simple-git's commandConfigPrefixingPlugin processes the configuration, converting it to -c trailer.exploit.cmd=<malicious_command>.
  5. blockUnsafeOperationsPlugin evaluates the arguments; it ignores trailer.*.cmd keys as they are missing from the preventUnsafeConfig list.
  6. The application executes a Git command (e.g., git interpret-trailers) with the injected configuration.
  7. The underlying Git binary executes the attacker-supplied shell command as the Node.js process.
  8. Attacker achieves remote code execution within the context of the application service.

Impact

Successful exploitation results in arbitrary command execution on the host running the Node.js application. The impact is limited only by the filesystem, network, and service permissions of the application process. Potential outcomes include exfiltration of local sensitive files, lateral movement within the environment, or full system compromise if the service runs with elevated privileges.

Recommendation

Prioritize the immediate audit of all code paths that utilize simple-git and pass user-supplied data into the config object or command arguments.

  • Update simple-git to version 4.0.1 or later once available, as this release remediates the missing matcher.
  • Implement an explicit allowlist for Git configuration keys instead of relying solely on the default blockUnsafeOperationsPlugin.
  • Ensure any application-level sanitization logic prevents the injection of trailer.*.cmd and trailer.*.command keys into simple-git configuration objects.
  • Deploy runtime monitoring for unexpected child processes spawned by Node.js applications that utilize Git, specifically looking for git spawning unexpected shell commands.

Immediate actions

Audit code for dynamic simple-git configuration usage

Development Teams 48h

Mitigations

Upgrade simple-git to 4.0.1 or newer

immediate IT Operations

CVE-2026-102828