SB2026041460 - OS Command Injection in Simple Git
Published: April 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS Command Injection (CVE-ID: CVE-2026-28291)
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper neutralization of special elements used in an os command in the option-parsing logic of simple-git when processing user-controlled git command options. A remote attacker can supply specially crafted option variants to execute arbitrary commands.
The issue can be triggered even when allowUnsafePack is explicitly set to false, and the provided proof of concept succeeded on Linux-based environments but was not reproduced on Windows 11.
Remediation
Install update from vendor's website.