High severity8.1NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026
CVE-2022-25912
CVE-2022-25912
Description
The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of CVE-2022-24066.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
simple-gitnpm | < 3.15.0 | 3.15.0 |
Affected products
3- cpe:2.3:a:simple-git_project:simple-git:*:*:*:*:*:node.js:*:*Range: <3.15.0
- simple-git/simple-gitdescription
Patches
Vulnerability mechanics
References
7- github.com/steveukx/git-js/commit/774648049eb3e628379e292ea172dccaba610504nvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3153532nvdExploitPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-9p95-fxvg-qgq2ghsaADVISORY
- github.com/steveukx/git-js/releases/tag/simple-git%403.15.0nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25912ghsaADVISORY
- github.com/steveukx/git-js/blob/main/docs/PLUGIN-UNSAFE-ACTIONS.md%23overriding-allowed-protocolsnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.