binautopsy · 0x00400420confidentialv24.04 · sha 9f4e…a2c1pgp 0x783E 8C5A
LIVE · incident intake operational pgp 5421 993B … EAB8 0385 lat EU-SW · 42ms tz UTC+01 · AD
uptime 99.98% queue 3 active · 2 pending last note · 2026-04-26

Research

Public-artifact autopsies, CVE exploitability briefs, and detection rule drops. Every piece is reproducible from published hashes.

BRIEF

CVE-2026-6951 in simple-git: why the popular PoC doesn’t pwn anything (and the env-var path that does)

Verdict: conditionally-exploitable. Vulnerable on simple-git ≤ 3.35.x with @simple-git/argv-parser ≤ 1.0.3 only when the attacker can influence the env passed to git (the .env(...) reach), the --template option, or specific constructor config keys. The popularly-circulated --config protocol.ext.allow=always PoC does NOT work — argv-parser blocks it. Defenders using that PoC to test their stack will reach […]