Simple Git
Vendor:
First CVE: Mar 11, 2022 · Active for 4 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
9.6
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Simple Git over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2022
4 years ago
Most Recent CVE
Apr 25, 2026
91 days ago
CVE Severity & Scoring
Simple Git7 CVEs
14%
86%
All CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6951CRITICAL Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-S | Apr 25, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-28292CRITICAL `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes | Mar 10, 2026 | 9.8 | 39 | NO | NO |
CVE-2022-25912CRITICAL The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vul | Dec 6, 2022 | 9.8 | 35 | NO | NO |
CVE-2022-25860CRITICAL Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanit | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-28291HIGH simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing | Apr 13, 2026 | 8.1 | 30 | NO | NO |
CVE-2022-24066CRITICAL The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which | Apr 1, 2022 | 9.8 | 25 | NO | NO |
CVE-2022-24433CRITICAL The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and bra | Mar 11, 2022 | 9.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Simple Git
Top CWEs
Versions
No cataloged versions.