{"ok":true,"trend":{"id":399354,"platform":"mastodon","region":"global","key":"🚨 cve-2026-102828 — cvss 9.2 critical simple-git, an interface for running git commands in any node.js application, enab","title":"🚨 CVE-2026-102828 — CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab","url":"https://mastodon.social/@stemshop/117356136012634401","first_seen":"2026-09-29T20:27:49.580164Z","last_seen":"2026-09-29T20:27:49.580164Z","last_rank":8,"peak_rank":8,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.7934375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical vulnerability, CVE-2026-102828 with a CVSS score of 9.2, has been disclosed in simple-git, a widely used Node.js library for running Git commands from JavaScript. Versions 3.15.0 through 4.0.1 are affected because the default blockUnsafeOperationsPlugin fails to classify certain trailer .cmd values, potentially allowing unsafe Git operations. Developers are being urged to check their dependency versions and update promptly.","why":"Developers are alarmed that a widely used, critical-rated flaw could expose Node.js applications to attacks via Git operations.","tone":"negative","entities":["simple-git","Node.js","Git"],"summarized_at":"2026-09-29T20:28:46.621228Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1546},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical vulnerability CVE-2026-102828 found in simple-git library","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-29T20:27:49.580164Z","rank":8,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117356136012634401","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-102828 — CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer. .cmd…","posted_at":"2026-09-29T20:08:44.609000Z","likes":0}],"elsewhere":[],"window":"7d"}}