simple-git's Unsafe-Operation Guard Misses `trailer.<token>.cmd`, Allowing Command Execution via Git Config
What happened
A GitHub Security Advisory (GHSA-x6jw-m9v5-85vh, tracked as CVE-2026-102828) reports that the popular Node.js library simple-git ships a default blockUnsafeOperationsPlugin intended to reject unsafe Git configuration values before they reach the Git binary, but the underlying matcher list in @simple-git/argv-parser does not recognize trailer.<token>.cmd as unsafe. Git documents this key as a shell command invoked by git interpret-trailers. Per the advisory, an application that passes untrusted data into SimpleGitOptions.config (which the library's own command-config-prefixing-plugin converts into -c key=value arguments before the guard runs) can have that value reach Git unblocked, resulting in execution of an attacker-supplied shell command as the Node.js process.
The advisory states the flaw exists from [email protected] (the first release with the unsafe-operation plugin) through the current latest release, 3.36.0, and remains present on main. No fixed version is identified, and the exploit status is noted as PoC-public.
Why it matters for defenders
simple-git is a widely used npm package for driving Git operations from Node.js applications, CI tooling, and automation services. Per the advisory, any application that forwards attacker-influenced values into simple-git's config options or inline -c arguments — and relies on the default unsafe-operation guard as its protection — is exposed to command execution bounded by the privileges of the Node.js process. This includes services that build Git configuration dynamically from user input, webhook payloads, or templated trailer values.
What defenders should watch for or do now
- Inventory applications and CI pipelines that depend on
simple-gitand determine whether any untrusted input (user-supplied strings, webhook data, PR metadata) can flow intoSimpleGitOptions.configor raw-carguments passed to Git commands. - Until an upstream fix lands, treat the default unsafe-operation plugin as non-exhaustive — do not rely on it alone; apply your own allowlist/denylist for configuration keys reaching
simple-git, explicitly blockingtrailer.*.cmdandtrailer.*.command. - Hunt for unexpected child-process spawns from Node.js services that embed Git tooling, particularly around
git interpret-trailersinvocations with unusual-c trailer.*arguments in process command-line logs. - Review any code paths that construct trailer values or commit-message metadata from external input before passing them through
simple-git.
Developing intel
This is a same-day advisory disclosure with no released remediation at time of writing; the vulnerable condition is confirmed present in the latest release and on main. Details may change as the maintainers respond. See the original advisory for full technical verification steps: GHSA-x6jw-m9v5-85vh.