Command injection in Simple Git - CVE-2026-102827
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper neutralization of special elements in a command in the blockUnsafeOperationsPlugin when processing attacker-influenced git push options. A remote attacker can supply an abbreviated --receive-pack or --exec option to execute arbitrary commands.
Exploitation can occur with a local or file remote, or with an attacker-influenced receive-pack target.