Security-Control Bypass in @simple-git/argv-parser via Unfiltered VISUAL Environment Variable
The @simple-git/argv-parser library fails to classify the VISUAL environment variable as an unsafe editor, allowing attackers to bypass security guards and execute arbitrary code during Git operations.
The @simple-git/argv-parser library (version 1.1.1 and earlier) contains a security-control bypass vulnerability in its unsafe editor detection mechanism. The library provides a plugin, blockUnsafeOperationsPlugin, intended to prevent the execution of attacker-influenced binaries by restricting environment variables that Git uses to resolve editors, such as EDITOR, GIT_EDITOR, and GIT_SEQUENCE_EDITOR.
However, the parser's denylist implementation at packages/argv-parser/src/env/parse-env.ts fails to include the VISUAL environment variable. Furthermore, the prepareEnv function filters environment variables by checking if they exist in the GitEnvKeys map or start with the git prefix. Because VISUAL is neither in the map nor prefixed with git, it is discarded before the vulnerability scanner can evaluate it. Since Git falls back to VISUAL when resolving an editor, an attacker can supply a malicious binary path via this variable to gain code execution as the host user, bypassing the intended security guard.
Attack Chain
- Attacker identifies a target application that uses
@simple-git/argv-parserand allows user-controlled input to influence the environment variables passed to a spawned Git process. - Attacker crafts a malicious environment object containing
VISUAL=/tmp/evileditorand aTERMvariable (set to a value other than 'dumb'). - Attacker triggers a Git operation that requires an editor, such as
git commit --amendorgit rebase -i. - The application passes the attacker-influenced environment to
parseEnvfor security validation. prepareEnvdrops theVISUALkey because it is not recognized as a known Git environment key or prefixed with 'git'.- The
vulnerabilityCheckfunction returns an empty list, incorrectly signaling that the operation is safe. - The application executes the Git child process with the attacker's environment.
- Git resolves the editor using the
VISUALvariable, launching the attacker's binary against repository files (e.g.,.git/COMMIT_EDITMSG) with the privileges of the host user.
Impact
The vulnerability allows an attacker to execute arbitrary binaries under the context of the user running the Git process. This leads to potential command execution, unauthorized modification of repository data, and potential lateral movement if the process runs in a privileged or CI/CD environment. The impact is dependent on the consuming application's data flow, specifically whether untrusted user input is allowed to modify the child process environment.
Recommendation
- Patch the application by updating
@simple-git/argv-parseronce a fix is released by the maintainer. - Apply a temporary hotfix to
packages/argv-parser/src/env/parse-env.tsby adding'visual': 'allowUnsafeEditor'to theGitEnvKeysmapping. - Update
docs/PLUGIN-UNSAFE-ACTIONS.mdto reflect thatVISUALis now considered an unsafe editor variable. - Audit consuming applications to ensure that user-supplied input is not directly forwarded into the environment of child processes.
- Consider explicitly setting a safe
core.editororGIT_EDITORin the Git environment to override theVISUALvariable, effectively disabling the attacker's fallback.
Immediate actions
Audit applications using @simple-git for environment variable injection vulnerabilities.
Mitigations
Manually add 'visual': 'allowUnsafeEditor' to GitEnvKeys in packages/argv-parser/src/env/parse-env.ts.
Security-control bypass via VISUAL variable