Incomplete List of Disallowed Inputs in Simple Git - CVE-2026-102828
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to an incomplete blacklist in the blockUnsafeOperationsPlugin when processing attacker-controlled trailer command configuration. A remote attacker can supply a trailer.<token>.cmd configuration value and invoke git interpret-trailers to execute arbitrary commands.
Exploitation requires an application to pass attacker-controlled configuration or command arguments to simple-git while the default unsafe-operation plugin is active, and the invoked Git binary must support trailer command behavior.