Reddit Programming
201 subscribers
1.22K photos
126K links
I will send you newest post from subreddit /r/programming
Download Telegram
simple-git npm package has a CVSS 9.8 RCE. 5M+ weekly downloads. check your lockfiles.
https://www.reddit.com/r/programming/comments/1rqldot/simplegit_npm_package_has_a_cvss_98_rce_5m_weekly/

<!-- SC_OFF -->CVE-2026-28292. remote code execution through a case-sensitivity bypass. found the writeup at https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292 simple-git is everywhere, CI/CD pipelines, deploy scripts, automation tools. the kind of dependency you forget you have until something like this drops. <!-- SC_ON --> submitted by /u/Amor_Advantage_3 (https://www.reddit.com/user/Amor_Advantage_3)
[link] (https://www.codeant.ai/security-research/security-research-simple-git-remote-code-execution-cve-2026-28292) [comments] (https://www.reddit.com/r/programming/comments/1rqldot/simplegit_npm_package_has_a_cvss_98_rce_5m_weekly/)