VDB
Sign up
HIGH8.1

GHSA-9p95-fxvg-qgq2

simple-git vulnerable to Remote Code Execution when enabling the ext transport protocol

Quick fix

GHSA-9p95-fxvg-qgq2 — simple-git: upgrade to the fixed version with the command below.

npm install simple-git@3.15.0

Details

The package simple-git before 3.15.0 is vulnerable to Remote Code Execution (RCE) when enabling the `ext` transport protocol, which makes it exploitable via `clone()` method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/simple-git
Introduced in: 0Fixed in: 3.15.0
Fixnpm install simple-git@3.15.0

References