<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:19:16.177494+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337389</id>
    <title>EUVD-2026-337389</title>
    <updated>2026-10-06T09:19:16.231585+00:00</updated>
    <content>EUVD-2026-337389</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337389"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28291</id>
    <title>fkie_cve-2026-28291</title>
    <updated>2026-10-06T09:19:16.231628+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as Git's flexible option parsing allows numerous character combinations (e.g., -vu, -4u, -nu) to circumvent the regular-expression-based blocklist in the unsafe operations plugin. Due to the virtually infinite number of valid option variants that Git accepts, a complete blocklist-based mitigation may be infeasible without fully emulating Git's option parsing behavior. This issue has been fixed in version 3.32.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jcxm-m3jx-f287</id>
    <title>GHSA-jcxm-m3jx-f287 — simple-git Affected by Command Execution via Option-Parsing Bypass</title>
    <updated>2026-10-06T09:19:16.231685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: simple-git</p>
<p>### Summary</p>
<p>simple-git enables running native Git commands from JavaScript. Some commands accept options that allow executing another command; because this is very dangerous, execution is denied unless the user explicitly allows it. This vulnerability allows a malicious actor who can control the options to execute other commands even in a “safe” state where the user has not explicitly allowed them. The vulnerability was introduced by an incorrect patch for CVE-2022-25860. It is *likely* to affect all versions prior to and including 3.28.0.</p>
<p>### Detail</p>
<p>This vulnerability was introduced by an incorrect patch for CVE-2022-25860.</p>
<p>It was reproduced in the following environment:</p>
<p>```</p>
<p>WSL Docker
node: v22.19.0
git: git version 2.39.5
simple-git: 3.28.0</p>
<p>````</p>
<p>The issue was not reproduced on Windows 11.</p>
<p>The `-u` option, like `--upload-pack`, allows a command to be executed.</p>
<p>Currently, the `-u` and `--upload-pack` options are blocked in the file `simple-git/src/lib/plugins/block-unsafe-operations-plugin.ts`.</p>
<p>```ts
function preventUploadPack(arg: string, method: string) {
   if (/^\s*--(upload|receive)-pack/.test(arg)) {
      throw new GitPluginError(
         undefined,
         'unsafe',
         `Use of --upload-pack or --receive-pack is not permitted without enabling allowUnsafePack`
      );
   }</p>
<p>if (method === 'clone' &amp;&amp; /^\s*-u\b/.test(arg)) {
      throw new GitPluginError(
         undefined,
         'unsafe',
         `Use of clone with option -u is not permitt…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jcxm-m3jx-f287"/>
  </entry>
</feed>
