Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @simple-git/argv-parser
  4. ›
  5. CVE-2026-102829

CVE-2026-102829: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection

October 5, 2026

GitEnvKeys in packages/argv-parser/src/env/parse-env.ts maps only editor, git_editor and git_sequence_editor to the allowUnsafeEditor category. prepareEnv keeps an environment entry only when its lowercased name is a known GitEnvKey or starts with git, so VISUAL is discarded before collectConfigVulnerabilities ever inspects it. Git, however, falls back to VISUAL when resolving an editor, so parseEnv({ VISUAL: '/tmp/evileditor' }) reports no vulnerability while an interactive Git operation will execute that binary.

In a consuming application the shape is: environment values derived from a request or job are forwarded into the child Git environment and classified by this parser before spawn. The parser exists to classify exactly such values, and the equivalent EDITOR or GIT_EDITOR value is rejected — so the attacker gains an editor substitution that the guard is specifically designed to block.

  • EDITOR -> classified allowUnsafeEditor (GitEnvKeys, lines 5-27)
  • GIT_EDITOR -> classified allowUnsafeEditor (GitEnvKeys, lines 5-27)
  • GIT_SEQUENCE_EDITOR -> classified allowUnsafeEditor (GitEnvKeys, lines 5-27)
  • VISUAL -> absent from GitEnvKeys; dropped by prepareEnv, lines 60-68 — no vulnerability emitted

References

  • github.com/advisories/GHSA-v5rq-49vh-5v5c
  • github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4
  • github.com/steveukx/git-js/pull/1201
  • github.com/steveukx/git-js/releases/tag/@simple-git/argv-parser@2.0.1
  • github.com/steveukx/git-js/security/advisories/GHSA-v5rq-49vh-5v5c
  • nvd.nist.gov/vuln/detail/CVE-2026-102829

Code Behaviors & Features

Detect and mitigate CVE-2026-102829 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.0.1

Fixed versions

  • 2.0.1

Solution

Upgrade to version 2.0.1 or above.

Impact 8.1 HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-184: Incomplete List of Disallowed Inputs
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

npm/@simple-git/argv-parser/CVE-2026-102829.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 06 Oct 2026 00:16:22 +0000.