Skip to content

Commit 71d8707

Browse files
authored
Merge pull request #167 from Tcode-Motion/fix-doctor-command-injection-15352732339458415151
🔒 Fix command injection in doctor command
2 parents c479a87 + 7c4d797 commit 71d8707

1 file changed

Lines changed: 4 additions & 8 deletions

File tree

‎cli/src/commands/doctor.rs‎

Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -176,12 +176,10 @@ impl DoctorContext {
176176
let extensions = [".txs", ".tsx", ".tech", ".tspkg"];
177177
for ext in &extensions {
178178
let output = std::process::Command::new("powershell")
179+
.env("EXT", ext)
179180
.args([
180181
"-Command",
181-
&format!(
182-
"Get-ItemProperty -Path 'HKCU:\\Software\\Classes\\{}' -ErrorAction SilentlyContinue | Select-Object -ExpandProperty '(default)' -ErrorAction SilentlyContinue",
183-
ext
184-
)
182+
"Get-ItemProperty -Path \"HKCU:\\Software\\Classes\\$env:EXT\" -ErrorAction SilentlyContinue | Select-Object -ExpandProperty '(default)' -ErrorAction SilentlyContinue"
185183
])
186184
.output();
187185

@@ -208,12 +206,10 @@ impl DoctorContext {
208206
println!(" Repairing user file associations...");
209207
for ext in &extensions {
210208
let _ = std::process::Command::new("powershell")
209+
.env("EXT", ext)
211210
.args([
212211
"-Command",
213-
&format!(
214-
"New-Item -Path 'HKCU:\\Software\\Classes\\{}' -Force -ErrorAction SilentlyContinue; Set-Item -Path 'HKCU:\\Software\\Classes\\{}' -Value 'TechScript.File'",
215-
ext, ext
216-
)
212+
"New-Item -Path \"HKCU:\\Software\\Classes\\$env:EXT\" -Force -ErrorAction SilentlyContinue; Set-Item -Path \"HKCU:\\Software\\Classes\\$env:EXT\" -Value 'TechScript.File'"
217213
])
218214
.output();
219215
}

0 commit comments

Comments
 (0)