Vendor
high
threat
Remote Code Execution via simple-git trailer.cmd Configuration
1 TTP 1 CVEThe simple-git library fails to block 'trailer.<token>.cmd' configuration in its unsafe-operation guard, enabling command injection when applications process untrusted user input.
exploited
simple-git
supply-chain
vulnerability
remote-code-execution
1t
1c
high
advisory
Security-Control Bypass in @simple-git/argv-parser via Unfiltered VISUAL Environment Variable
1 TTPThe @simple-git/argv-parser library fails to classify the VISUAL environment variable as an unsafe editor, allowing attackers to bypass security guards and execute arbitrary code during Git operations.
@simple-git/argv-parser
security-bypass
code-execution
git
supply-chain
1t