SCA: security update for simple-git (GHSA-g4wm-2vf7-vfgr)

high Tenable Cloud Security Plugin ID 472952

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- simple-git, an interface for running git commands in any node.js application, enables applications to
execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not
completely reject configuration includes supplied through customArgs to git.clone(). The missing
include.path classification permits Git to load an attacker-controlled configuration file, and the initial
remediation does not cover includeIf.<condition>.path, allowing the same file-loading primitive through a
conditional include. A loaded configuration can set an executable Git option such as core.sshCommand,
which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation
requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled
file that the process can read. This issue is fixed in 4.0.0. (CVE-2026-102826)

Solution

Update the simple-git library and its related packages to version 4.0.0 or later.

See Also

https://github.com/advisories/GHSA-g4wm-2vf7-vfgr

Plugin Details

Severity: High

ID: 472952

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-102826

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-102826