CVE-2022-25912

HIGH

simple-git < 3.15.0 - Remote Code Execution via Ext Transport Protocol in Clone Method

Title source: llm
STIX 2.1

Description

The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).

Scores

CVSS v3 8.1
EPSS 0.0278
EPSS Percentile 84.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
npm/simple-git 0 - 3.15.0npm
simple-git_project/simple-git < 3.15.0
Published Dec 06, 2022
Tracked Since Feb 18, 2026