{"id":"CVE-2026-102828","aliases":["GHSA-x6jw-m9v5-85vh"],"url":"https://o3.security/vulnerability/CVE-2026-102828","summary":"simple-git unsafe-operation guard does not block trailer command configuration","details":"## Affected product\n\nThe default `blockUnsafeOperationsPlugin` in `simple-git` when an application permits untrusted values to reach `SimpleGitOptions.config` or Git inline configuration arguments such as `-c <key>=<value>`.\n\n## Summary\n\n`trailer.<token>.cmd` is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a `GitPluginError`.\n\nGit documents `trailer.<token>.cmd` as a shell command invoked by `git interpret-trailers`. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.\n\n## Technical details\n\n`simple-git/src/lib/git-factory.ts` installs `commandConfigPrefixingPlugin` before `blockUnsafeOperationsPlugin`. The prefixing plugin in `simple-git/src/lib/plugins/command-config-prefixing-plugin.ts` turns every `SimpleGitOptions.config` entry into `-c <key>=<value>` before the unsafe-operation plugin evaluates the final argv.\n\nIn `simple-git@3.36.0`, `blockUnsafeOperationsPlugin` delegates to `@simple-git/argv-parser`. `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` compares parsed configuration writes against `preventUnsafeConfig`. That list has no matcher for `trailer.<token>.cmd`, so the invocation is allowed.\n\nGit v2.39.5's `Documentation/git-interpret-trailers.txt` states that `trailer.<token>.cmd` specifies a shell command called to generate or modify a trailer.\n\n## Preconditions\n\nThe application must use an affected `simple-git` version with the default unsafe-operation plugin active and must pass attacker-controlled data into instance configuration or Git command arguments that configure `trailer.<token>.cmd`.\n\nThe invoked Git binary must support the documented trailer-command behavior, and the application must execute `git interpret-trailers` with the attacker-controlled configuration in scope. The command runs with the operating-system identity and permissions of the Node.js process.\n\n## Verification\n\nUse an isolated test environment and a harmless executable test helper that records only its invocation.\n\n**Control:** Configure `core.editor=<test-helper>` through `SimpleGitOptions.config` and invoke a benign Git task. The default plugin should throw `GitPluginError` before spawning Git because `core.editor` is present in `preventUnsafeConfig`.\n\n**Bypass:** Configure `trailer.audit.cmd=<test-helper>` through the same option and invoke Git with the equivalent argv shape:\n\n`git -c trailer.audit.cmd=<test-helper> interpret-trailers --trailer audit:<value> <input-file>`\n\nA vulnerable build does not raise `GitPluginError`; Git invokes the test helper while processing the trailer. Confirm the helper invocation, then remove test artifacts.\n\n## Impact\n\nAn attacker who controls the stated configuration input can cause Git to execute a shell command as the Node.js application process. The impact is bounded by that process's filesystem, network, and service permissions. Applications that do not expose untrusted configuration or command arguments to `simple-git` are outside this threat model.\n\n## Affected versions\n\nCommit `6b3c631eadea81f80ed10f6dec7d19a9db4d7084` introduced the default unsafe-operation plugin, and `simple-git@3.15.0` is the first release confirmed to contain it. Its implementation only rejected `protocol.allow` configuration, leaving trailer-command configuration unblocked.\n\nThe latest `simple-git` release, `3.36.0`, still lacks a trailer-command matcher. The current `main` branch also lacks one. No released remediation was identified.\n\n## Remediation\n\nDefault-deny configuration keys that can trigger executable behavior, or add a dedicated unsafe category that rejects `trailer.<token>.cmd` before spawning Git unless the application explicitly opts in.\n\nEvaluate `trailer.<token>.command` alongside `.cmd`, because Git documents it as related command behavior. Add parser and integration tests for leading `-c`, configured instance prefixes, and `git config` write forms, asserting that no Git child process is spawned without an explicit unsafe opt-in.\n\n## Evidence\n\n- `simple-git@3.15.0` was released on 2022-11-12 and contains the initial unsafe-operation plugin.\n- `simple-git@3.36.0` was released on 2026-04-12; its parser source does not match `trailer.<token>.cmd`.\n- `main` retains the missing matcher in `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts`.\n- Git v2.39.5 documents the trailer command behavior in `Documentation/git-interpret-trailers.txt`.\n- PR #1167 expanded other configuration checks but did not add a trailer-command matcher and is not release-backed as a remediation.\n- This review verified repository, release, and source artifacts through GitHub; it did not independently execute the runtime reproduction.","published":"2026-09-29T18:43:19.086Z","modified":"2026-10-02T03:47:25.121233276Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"simple-git","fixedVersion":"4.0.1"}],"fix":{"url":"https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3","label":"steveukx/git-js@d762810"},"references":[{"type":"WEB","url":"https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102828.json"},{"type":"ADVISORY","url":"https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102828"},{"type":"FIX","url":"https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3"},{"type":"FIX","url":"https://github.com/steveukx/git-js/pull/1198"},{"type":"PACKAGE","url":"https://github.com/steveukx/git-js"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T03:47:25.121233276Z"}}