Security: steveukx/git-js
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
`VISUAL` editor environment variable is omitted from unsafe editor detection | pkg:npm/%40simple-git/argv-parser@1.1.1GHSA-v5rq-49vh-5v5c published
Sep 26, 2026 by steveukxHigh -
simple-git unsafe-operation guard does not block trailer command configurationGHSA-x6jw-m9v5-85vh published
Sep 26, 2026 by steveukxHigh -
unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)GHSA-858h-whjf-mvg5 published
Sep 26, 2026 by steveukxHigh -
RCE in simple-git 3.36.0 via customArgs include.path; pending PR #1167 fix misses the includeIf variantGHSA-g4wm-2vf7-vfgr published
Sep 26, 2026 by steveukxHigh -
blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCEGHSA-r275-fr43-pm7q published
Apr 12, 2026 by steveukxCritical -
Command Execution via Option-Parsing Bypass in simple-gitGHSA-jcxm-m3jx-f287 published
Apr 12, 2026 by steveukxHigh
Learn more about advisories related to steveukx/git-js in the GitHub Advisory Database