DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102829: CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

Vulnerability ID: CVE-2026-102829
CVSS Score: 9.2
Published: 2026-10-05

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

TL;DR

Omission of the VISUAL environment variable from the GitEnvKeys lookup registry allows an attacker-controlled VISUAL variable to bypass simple-git security checks, leading to arbitrary command execution when Git falls back to an interactive editor.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-78 / CWE-184
  • Attack Vector: Network
  • CVSS v4.0 Score: 9.2 (Critical)
  • EPSS Score: 0.00275 (Percentile: 18.07%)
  • Impact: Unauthenticated Remote Code Execution
  • Exploit Status: Proof of Concept
  • KEV Status: Not Listed

Affected Systems

  • Applications using simple-git with untrusted environment variables
  • Applications using @simple-git/argv-parser < 2.0.1
  • @simple-git/argv-parser: < 2.0.1 (Fixed in: 2.0.1)
  • simple-git: < 4.0.2 (Fixed in: 4.0.2)

Code Analysis

Commit: 68874c2

Add visual to GitEnvKeys mapped to allowUnsafeEditor

diff --git a/packages/argv-parser/src/env/parse-env.ts b/packages/argv-parser/src/env/parse-env.ts\nindex 5c7fa5e0..55b886b6 100644\n--- a/packages/argv-parser/src/env/parse-env.ts\n+++ b/packages/argv-parser/src/env/parse-env.ts\n@@ -22,6 +22,7 @@ const GitEnvKeys = {\n    'pager': 'allowUnsafePager',\n    'prefix': 'allowUnsafeConfigPaths',\n    'ssh_askpass': 'allowUnsafeAskPass',\n+   'visual': 'allowUnsafeEditor',\n } as const satisfies Record<string, VulnerabilityCategory>;
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade @simple-git/argv-parser to version 2.0.1 or higher.
  • Sanitize and strip environment parameters (VISUAL, EDITOR, GIT_EDITOR) before passing them to simple-git.
  • Enforce a static high-priority editor configuration like GIT_EDITOR=true.

Remediation Steps:

  1. Identify all applications utilizing simple-git or @simple-git/argv-parser.
  2. Execute 'npm update @simple-git/argv-parser' or 'npm install simple-git@latest'.
  3. Verify that the dependency tree resolves @simple-git/argv-parser to version 2.0.1 or above.
  4. Optionally implement input sanitization to strip user-controlled environment keys.

References


Read the full report for CVE-2026-102829 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)