logo

CVE-2022-25860 simple-git

Package

Manager: npm
Name: simple-git
Vulnerable Version: >=0 <3.16.0

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.32332 pctl0.96699

Details

Remote code execution in simple-git Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.

Metadata

Created: 2023-01-26T21:30:25Z
Modified: 2025-04-01T23:03:11Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-9w5j-4mwv-2wj8/GHSA-9w5j-4mwv-2wj8.json
CWE IDs: ["CWE-78", "CWE-94"]
Alternative ID: GHSA-9w5j-4mwv-2wj8
Finding: F184
Auto approve: 1