CVE-2022-25912 is a critical Remote Code Execution (RCE) vulnerability affecting the simple-git package in versions prior to 3.15.0. This flaw, an incomplete fix for a previous CVE, allows RCE when the 'ext' transport protocol is enabled and the clone() method is invoked. Rated 9.8 Critical (CVSSv3.1), it presents a low-complexity network attack vector that can lead to complete compromise of confidentiality, integrity, and availability. Although not yet in the CISA KEV catalog, it is on a "Hot List" and has generated significant community discussion, indicating high interest. Currently, no public exploit code is available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.15.0CPE matchmatch criteria | cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.