chiprook
← Security
SecurityOctober 7, 2026, 08:09

CVE-2026-6951: simple-git blocklist bypass via --config flag leads to RCE

A critical flaw in the simple-git npm library (8.7M weekly downloads) was assigned CVE-2026-6951 with a CVSS score of 9.8. The 2022 patch blocked only the short -c flag, but git treats --config as a full synonym, letting attackers inject protocol.ext.allow=always and execute arbitrary code. Fixed in version 3.36.0.

CVE-2026-6951: simple-git blocklist bypass via --config flag leads to RCE
#Simple-git#Npm#Git
Read next
Security

Langflow CVE-2026-12944: Scanner Blocklist Gap Leads to Root Code Execution

Security

Stave scanner finds 47 security issues in default S3 configs of Mastodon, Discourse and Chatwoot

Security

Citrix NetScaler Exploit Drops Web Shells, Steals Config Data

Security

NPM malware campaign MALFEX hits 40,000 downloads