CVE-2026-102827 simple-git 命令注入漏洞
影响攻击者可借 push 参数绕过校验执行任意命令
simple-git 是 Node.js 中用于执行 Git 命令的接口库。4.0.0 之前版本中,默认的 blockUnsafeOperationsPlugin 插件以字面量方式比对解析出的选项名与危险选项拼写,而 Git 本身接受无歧义的长选项缩写,导致攻击者可构造缩写形式的 push 参数绕过检测。该问题已在 4.0.0 中修复。
影响范围
simple-git 4.0.0 之前的版本;具体受影响版本范围以官方公告为准,暂无更多公开信息。
漏洞详情
漏洞类型为命令注入(安全校验绕过)。成因是 blockUnsafeOperationsPlugin 仅匹配完整的危险选项拼写(如 --receive-pack、--exec),未考虑 Git 支持的长选项缩写,而 clone 路径的缩写处理并未覆盖 push 路径。攻击者若能影响 push 参数,即可用缩写形式绕过 detectVulnerableFlags,使 git push 指向本地或 file 远程或攻击者可控的 receive-pack 目标,从而让 Git 调用攻击者指定的命令。
利用条件与风险
利用前提是应用将攻击者可控的参数传入 simple-git 的 push 操作,且运行环境可执行 Git 命令。实战中可导致远程命令执行,风险较高。
修复建议
升级 simple-git 至 4.0.0 或更高版本。临时缓解措施:避免将不可信输入直接作为 push 参数传入,并对传入的 Git 选项进行严格白名单校验,暂无其他公开信息。
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated –receive-pack or –exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.