The editor cannot be tricked into editing the wrong file as root by environment variables, because it is not running as root.
The security is an actual flaw in sudoedit, the wrapper script, not a fundamental issue with the environment you pass to the command.