Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for CVE-2022-25912 that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.
{
"github_reviewed_at": "2026-05-05T20:12:16Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-94"
],
"nvd_published_at": "2026-04-25T06:16:16Z",
"severity": "HIGH"
}