Oct 6, 2026·5 min read·4 visits
Omission of the VISUAL environment variable from the GitEnvKeys lookup registry allows an attacker-controlled VISUAL variable to bypass simple-git security checks, leading to arbitrary command execution when Git falls back to an interactive editor.
A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.
The Node.js library simple-git provides a fluent interface for executing Git commands within Node.js applications. To maintain system security, the underlying argument parser @simple-git/argv-parser implements strict sanitization routines. These routines filter ambient and user-supplied environment variables to prevent command injection and unauthorized execution of binary files.
By default, interactive operations such as commit amendments or interactive rebases spawn a terminal-based text editor. To prevent malicious commands from being executed during this transition, the library checks relevant environment variables against the allowUnsafeEditor configuration. If allowUnsafeEditor is false, unsafe editor values are neutralized or blocked.
However, a critical vulnerability arose because the registry of tracked environment variables omitted the standard VISUAL variable. This omission allowed the environment variable to pass through the validation layer without validation. If an application forwards attacker-controlled environment variables to simple-git, an attacker can achieve arbitrary remote code execution.
The vulnerability exists due to an incomplete blocklist/allowlist structure within the file packages/argv-parser/src/env/parse-env.ts. The implementation maintains a registry named GitEnvKeys that maps environment variables to security restriction categories such as allowUnsafeEditor or allowUnsafePager. This mapping determines which variables must undergo security checks before command execution.
Git relies on a specific sequence of fallbacks to launch an interactive editor. It checks GIT_EDITOR first, followed by the git configuration core.editor, then VISUAL, and finally EDITOR. While GIT_EDITOR and EDITOR were mapped to allowUnsafeEditor in the package's configuration, the VISUAL variable was completely omitted from the list.
When a child process is spawned, simple-git constructs the runtime environment using prepareEnv. This function cleans the environment by stripping variables that do not start with a git prefix or are not explicitly defined in the GitEnvKeys dictionary. Because visual was absent from GitEnvKeys, the parser did not check its contents against the security rules. The variable was propagated to the spawned Git process unmodified, allowing the bypass of allowUnsafeEditor restrictions.
The root of the flaw is found in the definition of GitEnvKeys. Before the patch was applied, the mapping array registered keys representing editors and pagers, but completely missed the visual variable. This meant any security policy configured for safe editor execution was ineffective against payloads supplied through the VISUAL environment variable.
Below is the comparison of the vulnerable and patched code states in packages/argv-parser/src/env/parse-env.ts:
// Vulnerable Code State
const GitEnvKeys = {
'editor': 'allowUnsafeEditor',
'git_editor': 'allowUnsafeEditor',
'git_sequence_editor': 'allowUnsafeEditor',
'pager': 'allowUnsafePager',
'prefix': 'allowUnsafeConfigPaths',
'ssh_askpass': 'allowUnsafeAskPass',
} as const satisfies Record<string, VulnerabilityCategory>;The corresponding patch explicitly registers visual to map to the allowUnsafeEditor category:
// Patched Code State
const GitEnvKeys = {
'editor': 'allowUnsafeEditor',
'git_editor': 'allowUnsafeEditor',
'git_sequence_editor': 'allowUnsafeEditor',
'pager': 'allowUnsafePager',
'prefix': 'allowUnsafeConfigPaths',
'ssh_askpass': 'allowUnsafeAskPass',
'visual': 'allowUnsafeEditor', // Fix: Maps VISUAL to the editor safety category
} as const satisfies Record<string, VulnerabilityCategory>;This simple addition ensures that whenever a command block contains the VISUAL variable, the input value is subjected to validation against unsafe shell patterns and command segments.
An exploit targeting this vulnerability requires that a Node.js application accept user-influenced properties or environment variables and forward them to a simple-git instance. This occurs frequently in applications that accept external configuration blocks, environment payloads, or dynamically generated execution parameters.
To trigger the vulnerability, the attacker passes the VISUAL variable mapped to a malicious command sequence, such as a shell command downloader or a local payload writer. The application must also trigger an operation that requires Git to launch an interactive editor. Common interactive actions include running git commit --amend or initiation of an interactive rebase.
When the Git child process is invoked, it evaluates the environment. Finding that GIT_EDITOR is unset and the git config does not restrict it, Git accesses VISUAL and executes the command string directly in the shell. The execution takes place with the OS-level permissions of the running Node.js application process.
The consequence of this flaw is remote command execution under the privileges of the Node.js process. In cloud or containerized environments, this can lead to total system compromise, credential exfiltration from local environments, and lateral movement within the network.
According to CVSS v4.0 metrics, this vulnerability is scored at 9.2 (Critical). The high score reflects the potential for unauthenticated remote code execution, although the attack complexity is classified as high due to the requirement for specific application behaviors that forward untrusted environment variables.
Because the vulnerability exists in a core helper dependency of simple-git, its reach extends to any downstream application that relies on simple-git for managing git operations with user-supplied environment configurations. Security teams must identify and patch all instances immediately to mitigate risks.
The primary remediation strategy is upgrading the @simple-git/argv-parser package to version 2.0.1 or later. Alternatively, updating the consuming library simple-git to its latest version will pull in the resolved dependency automatically. This closes the control bypass by ensuring VISUAL is systematically checked.
If patching is not immediately feasible, developers must implement strict validation on environment variables passed to simple-git APIs. Manually deleting keys like VISUAL, EDITOR, and GIT_EDITOR from custom environment blocks before passing them to the .env() chain prevents injection vectors.
Additionally, applications can explicitly define a safe, static global variable for GIT_EDITOR (e.g., GIT_EDITOR=true or /usr/bin/true) in the environment or Git configuration. Because Git evaluates GIT_EDITOR before VISUAL, this blocks Git from ever falling back to the unvalidated VISUAL variable, rendering the bypass ineffective.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N| Product | Affected Versions | Fixed Version |
|---|---|---|
@simple-git/argv-parser simple-git | < 2.0.1 | 2.0.1 |
simple-git simple-git | < 4.0.2 | 4.0.2 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-78 / CWE-184 |
| Attack Vector | Network |
| CVSS v4.0 Score | 9.2 (Critical) |
| EPSS Score | 0.00275 (Percentile: 18.07%) |
| Impact | Unauthenticated Remote Code Execution |
| Exploit Status | Proof of Concept |
| KEV Status | Not Listed |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Incomplete List of Disallowed Inputs
A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.
A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.
A state desynchronization (cache drift) vulnerability exists in the multimodal Inter-Process Communication (IPC) Least Recently Used (LRU) caches of vLLM. When a multimodal request fails validation after its media hash has been registered on the frontend but before the payload is committed to the backend engine core, the frontend and backend caches drift out of lockstep. A subsequent request reusing the same media triggers an assertion failure in the backend engine core, resulting in a complete denial of service.
CVE-2026-105750 is a medium-severity local file disclosure vulnerability affecting the Docling and Docling-Slim libraries. When processing HTML documents using the optional Playwright rendering backend, the application fail to validate and restrict request URIs using the file:// scheme. This permits an attacker supplying a crafted HTML file to access, render, and exfiltrate local system files.
CVE-2026-102598 is a security bypass and Denial of Service (DoS) vulnerability in the Werkzeug WSGI web application library. In versions prior to 3.1.9, the library's safe_join function fails to sanitize Windows reserved device names containing an empty NTFS Alternate Data Stream (ADS) marker (such as NUL:). This allows remote, unauthenticated attackers to trigger indefinite thread-blocking operations on Windows hosts, resulting in application-wide resource exhaustion.
A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.