Detects Node.js applications using simple-git 3.15.0–3.32.2 where the blockUnsafeOperationsPlugin regex is case-sensitive but git config keys are case-insensitive. Passing uppercase -c PROTOCOL.ALLOW=always bypasses the security check and enables the ext:: protocol, which executes arbitrary OS commands on the host machine.
Is your app exploitable through CVE-2026-28292?
Scan your domain free