CVE-2026-6951: simple-git blocklist bypass via --config flag leads to RCE
A critical flaw in the simple-git npm library (8.7M weekly downloads) was assigned CVE-2026-6951 with a CVSS score of 9.8. The 2022 patch blocked only the short -c flag, but git treats --config as a full synonym, letting attackers inject protocol.ext.allow=always and execute arbitrary code. Fixed in version 3.36.0.
- CVSS 9.8 (Critical), CWE-94 and CWE-88, affects simple-git versions below 3.36.0
- The 2022 fix for CVE-2022-25912 blocked only -c, not the --config synonym
- Exploit requires injecting protocol.ext.allow=always and an ext:: clone URL
- Disclosed on 2026-04-25, patched in version 3.36.0
Read next
Security