simple-git: VISUAL Editor Fallback Bypasses Unsafe-Editor Protection in @simple-git/argv-parser
A security advisory (GHSA-v5rq-49vh-5v5c, tracked as CVE-2026-102829) reports a control-bypass flaw in @simple-git/argv-parser, the package simple-git uses to detect unsafe editor environment variables before spawning Git. According to the report, the parser's GitEnvKeys denylist classifies EDITOR, GIT_EDITOR, and GIT_SEQUENCE_EDITOR as allowUnsafeEditor risks, but omits VISUAL — a variable Git also consults, and which takes precedence over EDITOR in Git's own resolution order. Because the parser's filtering logic only retains keys it already recognizes, a VISUAL value is dropped before any check runs, so vulnerabilityCheck() returns no findings and simple-git's blockUnsafeOperationsPlugin allows the Git child process to spawn.
Why It Matters
This affects any application using simple-git's default unsafe-operations guard that forwards attacker-influenced environment values into Git calls. If an attacker can control an environment variable that ends up passed to Git (directly or via a request/job pipeline), setting VISUAL to a malicious path achieves the same outcome the guard exists to prevent for EDITOR/GIT_EDITOR: on commands that open an editor — such as git commit --amend or git rebase -i — Git executes the attacker-chosen binary as the host user, operating against files like .git/COMMIT_EDITMSG or the rebase-todo file. No special configuration or opt-in is required; the report states this was reproduced against default options with no unsafe allowances enabled. A public PoC is noted as available.
What Defenders Should Watch For
- Inventory where your application or CI/CD pipelines use simple-git (or raw Git child processes) with environment values derived from user input, webhooks, or job parameters — especially before
commit,commit --amend, orrebase -ioperations. - Treat
VISUALthe same asEDITOR/GIT_EDITOR: audit and sanitize it anywhere environment variables are forwarded into Git child processes, rather than relying solely on the library's built-in guard. - Hunt for unexpected child processes spawned by
git(particularly short-lived helper scripts) during commit/rebase operations on hosts or build agents where environment input isn't tightly controlled. - Consider explicitly setting
GIT_EDITORorcore.editorin environments where Git invokes an editor programmatically, since both take precedence overVISUALand would neutralize this gap even before a patch is applied. - Track upstream for a fix adding
VISUAL(and watch for related discussion ofTERM, which the report notes also isn't classified and controls whether Git consultsVISUALat all).
This is developing intel based on a newly published advisory; details on patch availability may evolve. Review the full technical writeup and proof-of-concept at the original GHSA advisory.