Intel

AIKIDO-2026-455143

@simple-git/argv-parser is vulnerable to Command Injection

Command InjectionGHSA-v5rq-49vh-5v5c Published 2 days ago

81

High Risk

This Affects:

JS@simple-git/argv-parser
0.0.1 - 2.0.0
Fixed in 2.0.1
Are you affected? Scan for Free

TL;DR

@simple-git/argv-parser's parseEnv only puts EDITOR, GIT_EDITOR, and GIT_SEQUENCE_EDITOR in the allowUnsafeEditor category, and prepareEnv drops any environment entry whose lowercased name is not a known key or does not start with git. VISUAL is dropped before the unsafe editor check runs, even though git falls back to VISUAL when picking an editor. parseEnv({ VISUAL: '/tmp/evileditor' }) reports no vulnerability while an interactive git operation runs that binary. The fix adds visual to GitEnvKeys under allowUnsafeEditor.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application allows untrusted values into the VISUAL environment variable passed to git operations.

Background info

@simple-git/argv-parser is vulnerable to Command Injection in versions 0.0.1 - 2.0.0.

How to fix this

Upgrade the @simple-git/argv-parser library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform