@simple-git/argv-parser is vulnerable to Command Injection
81
High Risk
@simple-git/argv-parser's parseEnv only puts EDITOR, GIT_EDITOR, and GIT_SEQUENCE_EDITOR in the allowUnsafeEditor category, and prepareEnv drops any environment entry whose lowercased name is not a known key or does not start with git. VISUAL is dropped before the unsafe editor check runs, even though git falls back to VISUAL when picking an editor. parseEnv({ VISUAL: '/tmp/evileditor' }) reports no vulnerability while an interactive git operation runs that binary. The fix adds visual to GitEnvKeys under allowUnsafeEditor.
You are affected if you are using a version that falls within the vulnerable range and your application allows untrusted values into the VISUAL environment variable passed to git operations.
@simple-git/argv-parser is vulnerable to Command Injection in versions 0.0.1 - 2.0.0.
Upgrade the @simple-git/argv-parser library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.