{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/simple-git/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:simple_git:simple_git:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-102828"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["simple-git (3.15.0 - 4.0.0)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","remote-code-execution"],"_cs_type":"threat","_cs_vendors":["simple-git"],"content_html":"\u003cp\u003eThe \u003ccode\u003esimple-git\u003c/code\u003e library (versions 3.15.0 through 3.36.0) contains a vulnerability in its \u003ccode\u003eblockUnsafeOperationsPlugin\u003c/code\u003e that fails to classify \u003ccode\u003etrailer.\u0026lt;token\u0026gt;.cmd\u003c/code\u003e as a dangerous Git configuration option. Git supports trailer commands to dynamically generate or modify metadata during operations like \u003ccode\u003egit interpret-trailers\u003c/code\u003e. Because \u003ccode\u003esimple-git\u003c/code\u003e does not include this key in its \u003ccode\u003epreventUnsafeConfig\u003c/code\u003e blocklist, an application that allows untrusted user input to influence Git configuration (e.g., via \u003ccode\u003eSimpleGitOptions.config\u003c/code\u003e or inline \u003ccode\u003e-c\u003c/code\u003e arguments) can be coerced into executing arbitrary shell commands. When the \u003ccode\u003egit\u003c/code\u003e binary is invoked with these attacker-controlled trailers, it executes the specified command with the permissions and environment of the Node.js process. This affects applications that bridge user-supplied data to \u003ccode\u003esimple-git\u003c/code\u003e configuration parameters without strict validation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an application endpoint or input field that passes user-controlled strings into \u003ccode\u003esimple-git\u003c/code\u003e configuration parameters.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious configuration payload: \u003ccode\u003etrailer.exploit.cmd=\u0026lt;malicious_command\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe Node.js application accepts the input and initializes \u003ccode\u003esimple-git\u003c/code\u003e with the tainted configuration.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esimple-git\u003c/code\u003e's \u003ccode\u003ecommandConfigPrefixingPlugin\u003c/code\u003e processes the configuration, converting it to \u003ccode\u003e-c trailer.exploit.cmd=\u0026lt;malicious_command\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eblockUnsafeOperationsPlugin\u003c/code\u003e evaluates the arguments; it ignores \u003ccode\u003etrailer.*.cmd\u003c/code\u003e keys as they are missing from the \u003ccode\u003epreventUnsafeConfig\u003c/code\u003e list.\u003c/li\u003e\n\u003cli\u003eThe application executes a Git command (e.g., \u003ccode\u003egit interpret-trailers\u003c/code\u003e) with the injected configuration.\u003c/li\u003e\n\u003cli\u003eThe underlying Git binary executes the attacker-supplied shell command as the Node.js process.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution within the context of the application service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary command execution on the host running the Node.js application. The impact is limited only by the filesystem, network, and service permissions of the application process. Potential outcomes include exfiltration of local sensitive files, lateral movement within the environment, or full system compromise if the service runs with elevated privileges.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate audit of all code paths that utilize \u003ccode\u003esimple-git\u003c/code\u003e and pass user-supplied data into the \u003ccode\u003econfig\u003c/code\u003e object or command arguments.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003esimple-git\u003c/code\u003e to version 4.0.1 or later once available, as this release remediates the missing matcher.\u003c/li\u003e\n\u003cli\u003eImplement an explicit allowlist for Git configuration keys instead of relying solely on the default \u003ccode\u003eblockUnsafeOperationsPlugin\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure any application-level sanitization logic prevents the injection of \u003ccode\u003etrailer.*.cmd\u003c/code\u003e and \u003ccode\u003etrailer.*.command\u003c/code\u003e keys into \u003ccode\u003esimple-git\u003c/code\u003e configuration objects.\u003c/li\u003e\n\u003cli\u003eDeploy runtime monitoring for unexpected child processes spawned by Node.js applications that utilize Git, specifically looking for \u003ccode\u003egit\u003c/code\u003e spawning unexpected shell commands.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:42:03Z","date_published":"2026-10-06T00:42:03Z","id":"https://feed.craftedsignal.io/briefs/2026-10-simple-git-vulnerability/","summary":"The simple-git library fails to block 'trailer.\u003ctoken\u003e.cmd' configuration in its unsafe-operation guard, enabling command injection when applications process untrusted user input.","title":"Remote Code Execution via simple-git trailer.cmd Configuration","url":"https://feed.craftedsignal.io/briefs/2026-10-simple-git-vulnerability/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@simple-git/argv-parser (\u003c= 1.1.1)"],"_cs_severities":["high"],"_cs_tags":["security-bypass","code-execution","git","supply-chain"],"_cs_type":"advisory","_cs_vendors":["simple-git"],"content_html":"\u003cp\u003eThe @simple-git/argv-parser library (version 1.1.1 and earlier) contains a security-control bypass vulnerability in its unsafe editor detection mechanism. The library provides a plugin, \u003ccode\u003eblockUnsafeOperationsPlugin\u003c/code\u003e, intended to prevent the execution of attacker-influenced binaries by restricting environment variables that Git uses to resolve editors, such as \u003ccode\u003eEDITOR\u003c/code\u003e, \u003ccode\u003eGIT_EDITOR\u003c/code\u003e, and \u003ccode\u003eGIT_SEQUENCE_EDITOR\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eHowever, the parser's denylist implementation at \u003ccode\u003epackages/argv-parser/src/env/parse-env.ts\u003c/code\u003e fails to include the \u003ccode\u003eVISUAL\u003c/code\u003e environment variable. Furthermore, the \u003ccode\u003eprepareEnv\u003c/code\u003e function filters environment variables by checking if they exist in the \u003ccode\u003eGitEnvKeys\u003c/code\u003e map or start with the \u003ccode\u003egit\u003c/code\u003e prefix. Because \u003ccode\u003eVISUAL\u003c/code\u003e is neither in the map nor prefixed with \u003ccode\u003egit\u003c/code\u003e, it is discarded before the vulnerability scanner can evaluate it. Since Git falls back to \u003ccode\u003eVISUAL\u003c/code\u003e when resolving an editor, an attacker can supply a malicious binary path via this variable to gain code execution as the host user, bypassing the intended security guard.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application that uses \u003ccode\u003e@simple-git/argv-parser\u003c/code\u003e and allows user-controlled input to influence the environment variables passed to a spawned Git process.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious environment object containing \u003ccode\u003eVISUAL=/tmp/evileditor\u003c/code\u003e and a \u003ccode\u003eTERM\u003c/code\u003e variable (set to a value other than 'dumb').\u003c/li\u003e\n\u003cli\u003eAttacker triggers a Git operation that requires an editor, such as \u003ccode\u003egit commit --amend\u003c/code\u003e or \u003ccode\u003egit rebase -i\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application passes the attacker-influenced environment to \u003ccode\u003eparseEnv\u003c/code\u003e for security validation.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eprepareEnv\u003c/code\u003e drops the \u003ccode\u003eVISUAL\u003c/code\u003e key because it is not recognized as a known Git environment key or prefixed with 'git'.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003evulnerabilityCheck\u003c/code\u003e function returns an empty list, incorrectly signaling that the operation is safe.\u003c/li\u003e\n\u003cli\u003eThe application executes the Git child process with the attacker's environment.\u003c/li\u003e\n\u003cli\u003eGit resolves the editor using the \u003ccode\u003eVISUAL\u003c/code\u003e variable, launching the attacker's binary against repository files (e.g., \u003ccode\u003e.git/COMMIT_EDITMSG\u003c/code\u003e) with the privileges of the host user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an attacker to execute arbitrary binaries under the context of the user running the Git process. This leads to potential command execution, unauthorized modification of repository data, and potential lateral movement if the process runs in a privileged or CI/CD environment. The impact is dependent on the consuming application's data flow, specifically whether untrusted user input is allowed to modify the child process environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch the application by updating \u003ccode\u003e@simple-git/argv-parser\u003c/code\u003e once a fix is released by the maintainer.\u003c/li\u003e\n\u003cli\u003eApply a temporary hotfix to \u003ccode\u003epackages/argv-parser/src/env/parse-env.ts\u003c/code\u003e by adding \u003ccode\u003e'visual': 'allowUnsafeEditor'\u003c/code\u003e to the \u003ccode\u003eGitEnvKeys\u003c/code\u003e mapping.\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003edocs/PLUGIN-UNSAFE-ACTIONS.md\u003c/code\u003e to reflect that \u003ccode\u003eVISUAL\u003c/code\u003e is now considered an unsafe editor variable.\u003c/li\u003e\n\u003cli\u003eAudit consuming applications to ensure that user-supplied input is not directly forwarded into the environment of child processes.\u003c/li\u003e\n\u003cli\u003eConsider explicitly setting a safe \u003ccode\u003ecore.editor\u003c/code\u003e or \u003ccode\u003eGIT_EDITOR\u003c/code\u003e in the Git environment to override the \u003ccode\u003eVISUAL\u003c/code\u003e variable, effectively disabling the attacker's fallback.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T00:41:55Z","date_published":"2026-10-06T00:41:55Z","id":"https://feed.craftedsignal.io/briefs/2026-10-simple-git-visual-bypass/","summary":"The @simple-git/argv-parser library fails to classify the VISUAL environment variable as an unsafe editor, allowing attackers to bypass security guards and execute arbitrary code during Git operations.","title":"Security-Control Bypass in @simple-git/argv-parser via Unfiltered VISUAL Environment Variable","url":"https://feed.craftedsignal.io/briefs/2026-10-simple-git-visual-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Simple-Git","version":"https://jsonfeed.org/version/1.1"}