Description
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A consuming application that forwards attacker-influenced environment values can therefore allow Git to invoke an attacker-selected editor during operations such as commit amendment or interactive rebase when no higher-priority editor setting overrides VISUAL and Git's terminal prerequisites are met. The executable runs with the privileges of the Node.js process. This issue is fixed in argv-parser 2.0.1.
Published: 2026-09-29
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Steveukx
Steveukx git-js
Vendors & Products Steveukx
Steveukx git-js

Tue, 29 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A consuming application that forwards attacker-influenced environment values can therefore allow Git to invoke an attacker-selected editor during operations such as commit amendment or interactive rebase when no higher-priority editor setting overrides VISUAL and Git's terminal prerequisites are met. The executable runs with the privileges of the Node.js process. This issue is fixed in argv-parser 2.0.1.
Title simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
Weaknesses CWE-184
CWE-78
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T19:28:41.888Z

Reserved: 2026-09-29T17:25:25.265Z

Link: CVE-2026-102829

cve-icon Vulnrichment

Updated: 2026-09-30T19:28:28.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T19:17:25.367

Modified: 2026-09-30T20:17:24.433

Link: CVE-2026-102829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:15:08Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')