The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Autoshare For Twitter Plugin | — | Update autoshare-for-twitter plugin to version 1.3.0, or a newer patched version | May 15, 2025 | Dec 5, 2022 |
| Elasticpress Plugin | — | Update elasticpress plugin to version 4.4.1, or a newer patched version | May 15, 2025 | Dec 5, 2022 |
| Insert Special Characters Plugin | — | Update insert-special-characters plugin to version 1.0.6, or a newer patched version | May 15, 2025 | Dec 5, 2022 |
| Maps Block Apple Plugin | — | Update maps-block-apple plugin to version 1.1.0, or a newer patched version | May 15, 2025 | Dec 5, 2022 |
| Simple Podcasting Plugin | — | Update simple-podcasting plugin to version 1.4.0, or a newer patched version | May 15, 2025 | Dec 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub