## Affected product
The default `blockUnsafeOperationsPlugin` in `simple-git` when an application permits untrusted values to reach `SimpleGitOptions.config` or Git inline configuration arguments such as `-c <key>=<value>`.
## Summary
`trailer.<token>.cmd` is not recognized as unsafe by the default guard. Therefore, a configured inline value reaches Git without a `GitPluginError`.
Git documents `trailer.<token>.cmd` as a shell command invoked by `git interpret-trailers`. An application that relies on the default plugin to reject unsafe configuration can therefore execute a command supplied through an untrusted trailer-command configuration value.
## Technical details
`simple-git/src/lib/git-factory.ts` installs `commandConfigPrefixingPlugin` before `blockUnsafeOperationsPlugin`. The prefixing plugin in `simple-git/src/lib/plugins/command-config-prefixing-plugin.ts` turns every `SimpleGitOptions.config` entry into `-c <key>=<value>` before the unsafe-operation plugin evaluates the final argv.
In `
[email protected]`, `blockUnsafeOperationsPlugin` delegates to `@simple-git/argv-parser`. `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts` compares parsed configuration writes against `preventUnsafeConfig`. That list has no matcher for `trailer.<token>.cmd`, so the invocation is allowed.
Git v2.39.5's `Documentation/git-interpret-trailers.txt` states that `trailer.<token>.cmd` specifies a shell command called to generate or modify a trailer.
## Preconditions
The application must use an affected `simple-git` version with the default unsafe-operation plugin active and must pass attacker-controlled data into instance configuration or Git command arguments that configure `trailer.<token>.cmd`.
The invoked Git binary must support the documented trailer-command behavior, and the application must execute `git interpret-trailers` with the attacker-controlled configuration in scope. The command runs with the operating-system identity and permissions of the Node.js process.
## Verification
Use an isolated test environment and a harmless executable test helper that records only its invocation.
**Control:** Configure `core.editor=<test-helper>` through `SimpleGitOptions.config` and invoke a benign Git task. The default plugin should throw `GitPluginError` before spawning Git because `core.editor` is present in `preventUnsafeConfig`.
**Bypass:** Configure `trailer.audit.cmd=<test-helper>` through the same option and invoke Git with the equivalent argv shape:
`git -c trailer.audit.cmd=<test-helper> interpret-trailers --trailer audit:<value> <input-file>`
A vulnerable build does not raise `GitPluginError`; Git invokes the test helper while processing the trailer. Confirm the helper invocation, then remove test artifacts.
## Impact
An attacker who controls the stated configuration input can cause Git to execute a shell command as the Node.js application process. The impact is bounded by that process's filesystem, network, and service permissions. Applications that do not expose untrusted configuration or command arguments to `simple-git` are outside this threat model.
## Affected versions
Commit `6b3c631eadea81f80ed10f6dec7d19a9db4d7084` introduced the default unsafe-operation plugin, and `
[email protected]` is the first release confirmed to contain it. Its implementation only rejected `protocol.allow` configuration, leaving trailer-command configuration unblocked.
The latest `simple-git` release, `3.36.0`, still lacks a trailer-command matcher. The current `main` branch also lacks one. No released remediation was identified.
## Remediation
Default-deny configuration keys that can trigger executable behavior, or add a dedicated unsafe category that rejects `trailer.<token>.cmd` before spawning Git unless the application explicitly opts in.
Evaluate `trailer.<token>.command` alongside `.cmd`, because Git documents it as related command behavior. Add parser and integration tests for leading `-c`, configured instance prefixes, and `git config` write forms, asserting that no Git child process is spawned without an explicit unsafe opt-in.
## Evidence
- `
[email protected]` was released on 2022-11-12 and contains the initial unsafe-operation plugin.
- `
[email protected]` was released on 2026-04-12; its parser source does not match `trailer.<token>.cmd`.
- `main` retains the missing matcher in `packages/argv-parser/src/vulnerabilities/detect-vulnerable-config-writes.ts`.
- Git v2.39.5 documents the trailer command behavior in `Documentation/git-interpret-trailers.txt`.
- PR #1167 expanded other configuration checks but did not add a trailer-command matcher and is not release-backed as a remediation.
- This review verified repository, release, and source artifacts through GitHub; it did not independently execute the runtime reproduction.