GHSA-g4wm-2vf7-vfgr: simple-git allows command execution through unblocked Git configuration includes
Summary
A vulnerability in simple-git allows attackers to run arbitrary code by passing specially crafted arguments to the `git.clone()` function. The library fails to block the `-c include.path=<file>` option, which lets attackers load a malicious Git configuration file that can then execute commands during Git operations. Even in the upcoming fix (PR #1167), a flaw in the blocking logic means attackers can still bypass it using the conditional form `includeIf.<condition>.path`.
Solution / Mitigation
PR #1167 (merged to main 2026-05-10, not yet released to npm) adds `preventConfigBuilder('include.path', 'allowUnsafeInclude')` to the denylist. However, the source notes this fix is incomplete: 'The generated regex `/\s*include.path/` closes the plain spelling but does not match the conditional form `includeIf.<cond>.path`. The variant therefore survives the upcoming release if the regex is not tightened in the same cycle.'
Vulnerability Details
EPSS: 0.5%
Yes
October 5, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-g4wm-2vf7-vfgr
First tracked: October 5, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 72%