All verified exploits

CVE-2026-28292 RCE via Case-Sensitivity Bypass in blockUnsafeOperationsPlugin

Pentest critical simple-git Added cve-verified-cve-2026-28292

Detects Node.js applications using simple-git 3.15.0–3.32.2 where the blockUnsafeOperationsPlugin regex is case-sensitive but git config keys are case-insensitive. Passing uppercase -c PROTOCOL.ALLOW=always bypasses the security check and enables the ext:: protocol, which executes arbitrary OS commands on the host machine.

Is your app exploitable through CVE-2026-28292?

Scan your domain free