{"ok":true,"trend":{"id":399353,"platform":"mastodon","region":"global","key":"🚨 cve-2026-102829 — cvss 9.2 critical simple-git, an interface for running git commands in any node.js application, enab","title":"🚨 CVE-2026-102829 — CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab","url":"https://mastodon.social/@stemshop/117356136557021704","first_seen":"2026-09-29T20:27:49.580164Z","last_seen":"2026-09-29T20:27:49.580164Z","last_rank":7,"peak_rank":7,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.8359375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.","why":"A newly disclosed maximum-severity vulnerability in a popular npm package forces Node.js developers to assess exposure urgently.","tone":"neutral","entities":["simple-git","argv-parser","CVE-2026-102829","npm","Node.js"],"summarized_at":"2026-09-29T20:28:42.940178Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1546},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical CVE-2026-102829 flaw reported in simple-git","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-29T20:27:49.580164Z","rank":7,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117356136557021704","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-102829 — CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv…","posted_at":"2026-09-29T20:08:52.923000Z","likes":0}],"elsewhere":[],"window":"7d"}}