Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221).
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ads Txt Manager Plugin | ads-txt-manager-plugin-cve-2022-25860 | May 15, 2025 | Feb 23, 2023 | |
| Ads Txt Plugin | ads-txt-plugin-cve-2022-25860 | Jul 21, 2025 | Feb 23, 2023 | |
| Insecure Content Warning Plugin | insecure-content-warning-plugin-cve-2022-25860 | May 15, 2025 | Feb 23, 2023 | |
| Maps Block Apple Plugin | maps-block-apple-plugin-cve-2022-25860 | May 15, 2025 | Feb 23, 2023 | |
| Retro Winamp Block Plugin | retro-winamp-block-plugin-cve-2022-25860 | May 15, 2025 | Feb 23, 2023 | |
| Simple Local Avatars Plugin | simple-local-avatars-plugin-cve-2022-25860 | May 15, 2025 | Feb 23, 2023 | |
| Simple Podcasting Plugin | simple-podcasting-plugin-cve-2022-25860 | May 15, 2025 | Feb 23, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub