CVE-2026-28292 is a critical remote code execution (RCE) vulnerability affecting `simple-git` versions 3.15.0 through 3.32.2, a Node.js library for executing Git commands. This flaw allows an unauthenticated attacker to bypass prior security fixes (CVE-2022-25860 and CVE-2022-25912), achieving full RCE on the host machine. With a CVSS score of 9.8 Critical, the vulnerability has a network-based attack vector with low complexity and no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community attention, and it is not listed on the CISA KEV catalog. Organizations using affected versions should consider upgrading, as version 3.23.0 contains an updated fix for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.15.0, < 3.32.2CPE matchmatch criteria | cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.