CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser
Vulnerability ID: CVE-2026-102829
CVSS Score: 9.2
Published: 2026-10-05
A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.
TL;DR
Omission of the VISUAL environment variable from the GitEnvKeys lookup registry allows an attacker-controlled VISUAL variable to bypass simple-git security checks, leading to arbitrary command execution when Git falls back to an interactive editor.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-78 / CWE-184
- Attack Vector: Network
- CVSS v4.0 Score: 9.2 (Critical)
- EPSS Score: 0.00275 (Percentile: 18.07%)
- Impact: Unauthenticated Remote Code Execution
- Exploit Status: Proof of Concept
- KEV Status: Not Listed
Affected Systems
- Applications using simple-git with untrusted environment variables
- Applications using @simple-git/argv-parser < 2.0.1
-
@simple-git/argv-parser: < 2.0.1 (Fixed in:
2.0.1) -
simple-git: < 4.0.2 (Fixed in:
4.0.2)
Code Analysis
Commit: 68874c2
Add visual to GitEnvKeys mapped to allowUnsafeEditor
diff --git a/packages/argv-parser/src/env/parse-env.ts b/packages/argv-parser/src/env/parse-env.ts\nindex 5c7fa5e0..55b886b6 100644\n--- a/packages/argv-parser/src/env/parse-env.ts\n+++ b/packages/argv-parser/src/env/parse-env.ts\n@@ -22,6 +22,7 @@ const GitEnvKeys = {\n 'pager': 'allowUnsafePager',\n 'prefix': 'allowUnsafeConfigPaths',\n 'ssh_askpass': 'allowUnsafeAskPass',\n+ 'visual': 'allowUnsafeEditor',\n } as const satisfies Record<string, VulnerabilityCategory>;
Mitigation Strategies
- Upgrade @simple-git/argv-parser to version 2.0.1 or higher.
- Sanitize and strip environment parameters (VISUAL, EDITOR, GIT_EDITOR) before passing them to simple-git.
- Enforce a static high-priority editor configuration like GIT_EDITOR=true.
Remediation Steps:
- Identify all applications utilizing simple-git or @simple-git/argv-parser.
- Execute 'npm update @simple-git/argv-parser' or 'npm install simple-git@latest'.
- Verify that the dependency tree resolves @simple-git/argv-parser to version 2.0.1 or above.
- Optionally implement input sanitization to strip user-controlled environment keys.
References
Read the full report for CVE-2026-102829 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)