Skip to content

Commit 1cc58b4

Browse files
authored
Merge pull request #40 from Tcode-Motion/fix-command-injection-6640346681076279577
🔒 Fix command injection vulnerability in stdlib process.spawn
2 parents b4792c7 + 091e712 commit 1cc58b4

4 files changed

Lines changed: 22 additions & 3 deletions

File tree

‎Cargo.lock‎

Lines changed: 1 addition & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎stdlib/Cargo.toml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,3 +36,4 @@ uuid = { version = "1", features = ["v4"] }
3636
rustls = { version = "0.23", optional = true }
3737
tokio = { version = "1", features = ["rt", "macros", "sync", "time"], optional = true }
3838
hex = "0.4.3"
39+
shlex = "2.0.1"

‎stdlib/src/process.rs‎

Lines changed: 19 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -114,8 +114,25 @@ impl StdlibRegistry {
114114
))
115115
}
116116
};
117-
Command::new("cmd")
118-
.args(["/C", &cmd])
117+
118+
let parsed = shlex::split(&cmd).ok_or_else(|| {
119+
RuntimeError::new(
120+
RuntimeErrorKind::InvalidOperation("Failed to parse command string".to_string()),
121+
None,
122+
None,
123+
)
124+
})?;
125+
126+
if parsed.is_empty() {
127+
return Err(RuntimeError::new(
128+
RuntimeErrorKind::InvalidOperation("Empty command string".to_string()),
129+
None,
130+
None,
131+
));
132+
}
133+
134+
Command::new(&parsed[0])
135+
.args(&parsed[1..])
119136
.spawn()
120137
.map_err(|e| {
121138
RuntimeError::new(

‎stdlib/tests/stdlib_tests.rs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
use std::cell::RefCell;
22
use std::collections::HashSet;
33
use std::rc::Rc;
4-
use techscript_runtime::{context::Capability, value::RuntimeValue, RuntimeConfig, RuntimeContext};
4+
use techscript_runtime::{context::Capability, value::RuntimeValue, RuntimeConfig, RuntimeContext, error::RuntimeErrorKind};
55
use techscript_stdlib::StdlibRegistry;
66

77
#[test]

0 commit comments

Comments
 (0)