The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).
Metrics
Affected Vendors & Products
References
History
Tue, 22 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: snyk
Published: 2022-12-12T01:49:10.008Z
Updated: 2025-04-22T20:15:14.996Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25912

Updated: 2024-08-03T04:49:44.459Z

Status : Modified
Published: 2022-12-06T05:15:11.570
Modified: 2025-04-22T21:15:42.690
Link: CVE-2022-25912

No data.