CVE-2026-102826 simple-git 配置注入导致命令执行漏洞
影响攻击者可借助恶意配置在克隆时执行任意命令
simple-git 是 Node.js 中用于执行 Git 命令的库。4.0.0 之前版本中,默认的 blockUnsafeOperationsPlugin 未能完全拦截通过 customArgs 传入 git.clone() 的配置 include,导致 Git 可加载攻击者控制的配置文件。该问题在 4.0.0 中修复。
影响范围
漏洞详情
漏洞类型为配置注入导致的命令执行。由于 include.path 与 includeIf.<condition>.path 未被正确分类拦截,攻击者可让 Git 加载恶意配置文件,并设置 core.sshCommand 等可执行选项,Git 在克隆时会以 Node.js 进程权限调用该命令。
利用条件与风险
利用需应用将攻击者可控参数传入 customArgs,且存在进程可读取的攻击者可控文件,条件满足时可导致远程命令执行,风险较高。
修复建议
升级 simple-git 至 4.0.0 或更高版本;临时缓解措施为不要将不可信输入传入 customArgs,并限制 Git 配置 include 相关选项。
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf..path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0.