<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Simple-Git - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/simple-git/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:42:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/simple-git/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution via simple-git trailer.cmd Configuration</title><link>https://feed.craftedsignal.io/briefs/2026-10-simple-git-vulnerability/</link><pubDate>Tue, 06 Oct 2026 00:42:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-simple-git-vulnerability/</guid><description>The simple-git library fails to block 'trailer.&lt;token&gt;.cmd' configuration in its unsafe-operation guard, enabling command injection when applications process untrusted user input.</description><content:encoded><![CDATA[<p>The <code>simple-git</code> library (versions 3.15.0 through 3.36.0) contains a vulnerability in its <code>blockUnsafeOperationsPlugin</code> that fails to classify <code>trailer.&lt;token&gt;.cmd</code> as a dangerous Git configuration option. Git supports trailer commands to dynamically generate or modify metadata during operations like <code>git interpret-trailers</code>. Because <code>simple-git</code> does not include this key in its <code>preventUnsafeConfig</code> blocklist, an application that allows untrusted user input to influence Git configuration (e.g., via <code>SimpleGitOptions.config</code> or inline <code>-c</code> arguments) can be coerced into executing arbitrary shell commands. When the <code>git</code> binary is invoked with these attacker-controlled trailers, it executes the specified command with the permissions and environment of the Node.js process. This affects applications that bridge user-supplied data to <code>simple-git</code> configuration parameters without strict validation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an application endpoint or input field that passes user-controlled strings into <code>simple-git</code> configuration parameters.</li>
<li>Attacker crafts a malicious configuration payload: <code>trailer.exploit.cmd=&lt;malicious_command&gt;</code>.</li>
<li>The Node.js application accepts the input and initializes <code>simple-git</code> with the tainted configuration.</li>
<li><code>simple-git</code>'s <code>commandConfigPrefixingPlugin</code> processes the configuration, converting it to <code>-c trailer.exploit.cmd=&lt;malicious_command&gt;</code>.</li>
<li><code>blockUnsafeOperationsPlugin</code> evaluates the arguments; it ignores <code>trailer.*.cmd</code> keys as they are missing from the <code>preventUnsafeConfig</code> list.</li>
<li>The application executes a Git command (e.g., <code>git interpret-trailers</code>) with the injected configuration.</li>
<li>The underlying Git binary executes the attacker-supplied shell command as the Node.js process.</li>
<li>Attacker achieves remote code execution within the context of the application service.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary command execution on the host running the Node.js application. The impact is limited only by the filesystem, network, and service permissions of the application process. Potential outcomes include exfiltration of local sensitive files, lateral movement within the environment, or full system compromise if the service runs with elevated privileges.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate audit of all code paths that utilize <code>simple-git</code> and pass user-supplied data into the <code>config</code> object or command arguments.</p>
<ul>
<li>Update <code>simple-git</code> to version 4.0.1 or later once available, as this release remediates the missing matcher.</li>
<li>Implement an explicit allowlist for Git configuration keys instead of relying solely on the default <code>blockUnsafeOperationsPlugin</code>.</li>
<li>Ensure any application-level sanitization logic prevents the injection of <code>trailer.*.cmd</code> and <code>trailer.*.command</code> keys into <code>simple-git</code> configuration objects.</li>
<li>Deploy runtime monitoring for unexpected child processes spawned by Node.js applications that utilize Git, specifically looking for <code>git</code> spawning unexpected shell commands.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>supply-chain</category><category>vulnerability</category><category>remote-code-execution</category></item><item><title>Security-Control Bypass in @simple-git/argv-parser via Unfiltered VISUAL Environment Variable</title><link>https://feed.craftedsignal.io/briefs/2026-10-simple-git-visual-bypass/</link><pubDate>Tue, 06 Oct 2026 00:41:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-simple-git-visual-bypass/</guid><description>The @simple-git/argv-parser library fails to classify the VISUAL environment variable as an unsafe editor, allowing attackers to bypass security guards and execute arbitrary code during Git operations.</description><content:encoded><![CDATA[<p>The @simple-git/argv-parser library (version 1.1.1 and earlier) contains a security-control bypass vulnerability in its unsafe editor detection mechanism. The library provides a plugin, <code>blockUnsafeOperationsPlugin</code>, intended to prevent the execution of attacker-influenced binaries by restricting environment variables that Git uses to resolve editors, such as <code>EDITOR</code>, <code>GIT_EDITOR</code>, and <code>GIT_SEQUENCE_EDITOR</code>.</p>
<p>However, the parser's denylist implementation at <code>packages/argv-parser/src/env/parse-env.ts</code> fails to include the <code>VISUAL</code> environment variable. Furthermore, the <code>prepareEnv</code> function filters environment variables by checking if they exist in the <code>GitEnvKeys</code> map or start with the <code>git</code> prefix. Because <code>VISUAL</code> is neither in the map nor prefixed with <code>git</code>, it is discarded before the vulnerability scanner can evaluate it. Since Git falls back to <code>VISUAL</code> when resolving an editor, an attacker can supply a malicious binary path via this variable to gain code execution as the host user, bypassing the intended security guard.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target application that uses <code>@simple-git/argv-parser</code> and allows user-controlled input to influence the environment variables passed to a spawned Git process.</li>
<li>Attacker crafts a malicious environment object containing <code>VISUAL=/tmp/evileditor</code> and a <code>TERM</code> variable (set to a value other than 'dumb').</li>
<li>Attacker triggers a Git operation that requires an editor, such as <code>git commit --amend</code> or <code>git rebase -i</code>.</li>
<li>The application passes the attacker-influenced environment to <code>parseEnv</code> for security validation.</li>
<li><code>prepareEnv</code> drops the <code>VISUAL</code> key because it is not recognized as a known Git environment key or prefixed with 'git'.</li>
<li>The <code>vulnerabilityCheck</code> function returns an empty list, incorrectly signaling that the operation is safe.</li>
<li>The application executes the Git child process with the attacker's environment.</li>
<li>Git resolves the editor using the <code>VISUAL</code> variable, launching the attacker's binary against repository files (e.g., <code>.git/COMMIT_EDITMSG</code>) with the privileges of the host user.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an attacker to execute arbitrary binaries under the context of the user running the Git process. This leads to potential command execution, unauthorized modification of repository data, and potential lateral movement if the process runs in a privileged or CI/CD environment. The impact is dependent on the consuming application's data flow, specifically whether untrusted user input is allowed to modify the child process environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch the application by updating <code>@simple-git/argv-parser</code> once a fix is released by the maintainer.</li>
<li>Apply a temporary hotfix to <code>packages/argv-parser/src/env/parse-env.ts</code> by adding <code>'visual': 'allowUnsafeEditor'</code> to the <code>GitEnvKeys</code> mapping.</li>
<li>Update <code>docs/PLUGIN-UNSAFE-ACTIONS.md</code> to reflect that <code>VISUAL</code> is now considered an unsafe editor variable.</li>
<li>Audit consuming applications to ensure that user-supplied input is not directly forwarded into the environment of child processes.</li>
<li>Consider explicitly setting a safe <code>core.editor</code> or <code>GIT_EDITOR</code> in the Git environment to override the <code>VISUAL</code> variable, effectively disabling the attacker's fallback.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>security-bypass</category><category>code-execution</category><category>git</category><category>supply-chain</category></item></channel></rss>