CVE-2022-25860 – simple-git
Package
Manager: npm
Name: simple-git
Vulnerable Version: >=0 <3.16.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.32332 pctl0.96699
Details
Remote code execution in simple-git Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of CVE-2022-25912.
Metadata
Created: 2023-01-26T21:30:25Z
Modified: 2025-04-01T23:03:11Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-9w5j-4mwv-2wj8/GHSA-9w5j-4mwv-2wj8.json
CWE IDs: ["CWE-78", "CWE-94"]
Alternative ID: GHSA-9w5j-4mwv-2wj8
Finding: F184
Auto approve: 1