← Blog · · df00tech

simple-git's Unsafe-Operation Guard Misses `trailer.<token>.cmd`, Allowing Command Execution via Git Config

breaking ghsa npm CVE-2026-102828

What happened

A GitHub Security Advisory (GHSA-x6jw-m9v5-85vh, tracked as CVE-2026-102828) reports that the popular Node.js library simple-git ships a default blockUnsafeOperationsPlugin intended to reject unsafe Git configuration values before they reach the Git binary, but the underlying matcher list in @simple-git/argv-parser does not recognize trailer.<token>.cmd as unsafe. Git documents this key as a shell command invoked by git interpret-trailers. Per the advisory, an application that passes untrusted data into SimpleGitOptions.config (which the library's own command-config-prefixing-plugin converts into -c key=value arguments before the guard runs) can have that value reach Git unblocked, resulting in execution of an attacker-supplied shell command as the Node.js process.

The advisory states the flaw exists from [email protected] (the first release with the unsafe-operation plugin) through the current latest release, 3.36.0, and remains present on main. No fixed version is identified, and the exploit status is noted as PoC-public.

Why it matters for defenders

simple-git is a widely used npm package for driving Git operations from Node.js applications, CI tooling, and automation services. Per the advisory, any application that forwards attacker-influenced values into simple-git's config options or inline -c arguments — and relies on the default unsafe-operation guard as its protection — is exposed to command execution bounded by the privileges of the Node.js process. This includes services that build Git configuration dynamically from user input, webhook payloads, or templated trailer values.

What defenders should watch for or do now

  • Inventory applications and CI pipelines that depend on simple-git and determine whether any untrusted input (user-supplied strings, webhook data, PR metadata) can flow into SimpleGitOptions.config or raw -c arguments passed to Git commands.
  • Until an upstream fix lands, treat the default unsafe-operation plugin as non-exhaustive — do not rely on it alone; apply your own allowlist/denylist for configuration keys reaching simple-git, explicitly blocking trailer.*.cmd and trailer.*.command.
  • Hunt for unexpected child-process spawns from Node.js services that embed Git tooling, particularly around git interpret-trailers invocations with unusual -c trailer.* arguments in process command-line logs.
  • Review any code paths that construct trailer values or commit-message metadata from external input before passing them through simple-git.

Developing intel

This is a same-day advisory disclosure with no released remediation at time of writing; the vulnerable condition is confirmed present in the latest release and on main. Details may change as the maintainers respond. See the original advisory for full technical verification steps: GHSA-x6jw-m9v5-85vh.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.