Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Simple Git Project

First CVE: Mar 11, 2022Active for: 4 yearsTotal CVEs: 11

Simple Git Project maintains a focused, widely used Git library that serves as a foundational component across numerous Node.js applications and development tools, despite being a single-product offering. The vendor's vulnerability exposure reflects the parsing and command-execution complexity inherent to a Git abstraction layer operating at the application layer. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
9.6
Avg CVSS Score
Higher Avg CVSS Score than 90% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Simple Git Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2022
4 years ago
Most Recent CVE
Apr 25, 2026
90 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-6951CRITICAL
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-S
Apr 25, 20269.842NONO
CVE-2026-28292CRITICAL
`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes
Mar 10, 20269.839NONO
CVE-2022-25912CRITICAL
The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vul
Dec 6, 20229.835NONO
CVE-2022-25860CRITICAL
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanit
Jan 26, 20239.831NONO
CVE-2026-28291HIGH
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing
Apr 13, 20268.130NONO
CVE-2022-24066CRITICAL
The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which
Apr 1, 20229.825NONO
CVE-2022-24433CRITICAL
The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and bra
Mar 11, 20229.825NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
86%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Git Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Simple Git Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Simple Git Project's Products

View all 2 CNAs →

Top CWEs