CVE-2026-102829: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
GitEnvKeys in packages/argv-parser/src/env/parse-env.ts maps only editor, git_editor and git_sequence_editor to the allowUnsafeEditor category. prepareEnv keeps an environment entry only when its lowercased name is a known GitEnvKey or starts with git, so VISUAL is discarded before collectConfigVulnerabilities ever inspects it. Git, however, falls back to VISUAL when resolving an editor, so parseEnv({ VISUAL: '/tmp/evileditor' }) reports no vulnerability while an interactive Git operation will execute that binary.
In a consuming application the shape is: environment values derived from a request or job are forwarded into the child Git environment and classified by this parser before spawn. The parser exists to classify exactly such values, and the equivalent EDITOR or GIT_EDITOR value is rejected — so the attacker gains an editor substitution that the guard is specifically designed to block.
EDITOR-> classifiedallowUnsafeEditor(GitEnvKeys, lines 5-27)GIT_EDITOR-> classifiedallowUnsafeEditor(GitEnvKeys, lines 5-27)GIT_SEQUENCE_EDITOR-> classifiedallowUnsafeEditor(GitEnvKeys, lines 5-27)VISUAL-> absent fromGitEnvKeys; dropped byprepareEnv, lines 60-68 — no vulnerability emitted
References
- github.com/advisories/GHSA-v5rq-49vh-5v5c
- github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4
- github.com/steveukx/git-js/pull/1201
- github.com/steveukx/git-js/releases/tag/@simple-git/argv-parser@2.0.1
- github.com/steveukx/git-js/security/advisories/GHSA-v5rq-49vh-5v5c
- nvd.nist.gov/vuln/detail/CVE-2026-102829
Code Behaviors & Features
Detect and mitigate CVE-2026-102829 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →