Vulnerability in simple-git Node.js Package Allows Execution of Attacker-selected Editor
CVE-2026-102829
What is CVE-2026-102829?
The simple-git interface allows Node.js applications to execute git commands. A vulnerability prior to version 2.0.1 in the argv-parser package allows omitted environment variables to be exploited. Specifically, the VISUAL variable, which is intended to specify the default editor, can be manipulated through attacker-influenced environment settings. If a Node.js application forwards these settings without proper validation, it could invoke a malicious editor during operations such as commit amendments or interactive rebases. This executable would run with the privileges of the Node.js process, potentially allowing unauthorized actions and compromising application security. The issue is addressed in argv-parser version 2.0.1, which corrects the oversight.
Affected Version(s)
git-js < 2.0.1
