Vulnerability in simple-git Node.js Package Allows Execution of Attacker-selected Editor
CVE-2026-102829

9.2CRITICAL

Key Information:

Vendor

Steveukx

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102829?

The simple-git interface allows Node.js applications to execute git commands. A vulnerability prior to version 2.0.1 in the argv-parser package allows omitted environment variables to be exploited. Specifically, the VISUAL variable, which is intended to specify the default editor, can be manipulated through attacker-influenced environment settings. If a Node.js application forwards these settings without proper validation, it could invoke a malicious editor during operations such as commit amendments or interactive rebases. This executable would run with the privileges of the Node.js process, potentially allowing unauthorized actions and compromising application security. The issue is addressed in argv-parser version 2.0.1, which corrects the oversight.

Affected Version(s)

git-js < 2.0.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.