SCA: security update for simple-git (GHSA-858h-whjf-mvg5)

high Tenable Self-Hosted Container Security Plugin ID 472980

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- simple-git, an interface for running git commands in any node.js application, enables applications to
execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares
parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option
abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can
therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-
influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that
expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is
fixed in 4.0.0. (CVE-2026-102827)

Solution

Update the simple-git library and its related packages to version 4.0.0 or later.

See Also

https://github.com/advisories/GHSA-858h-whjf-mvg5

Plugin Details

Severity: High

ID: 472980

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-102827

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-102827