From 7c4d797128f477afd24b68a81d7990952c7e06cc Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Tue, 15 Sep 2026 08:42:22 +0000 Subject: [PATCH] Fix command injection vulnerability in doctor command Replaces insecure format! string interpolation with secure environment variable injection for passing extensions to PowerShell commands in check_windows_associations. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- cli/src/commands/doctor.rs | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/cli/src/commands/doctor.rs b/cli/src/commands/doctor.rs index 45bcf7bb..243aa876 100644 --- a/cli/src/commands/doctor.rs +++ b/cli/src/commands/doctor.rs @@ -176,12 +176,10 @@ impl DoctorContext { let extensions = [".txs", ".tsx", ".tech", ".tspkg"]; for ext in &extensions { let output = std::process::Command::new("powershell") + .env("EXT", ext) .args([ "-Command", - &format!( - "Get-ItemProperty -Path 'HKCU:\\Software\\Classes\\{}' -ErrorAction SilentlyContinue | Select-Object -ExpandProperty '(default)' -ErrorAction SilentlyContinue", - ext - ) + "Get-ItemProperty -Path \"HKCU:\\Software\\Classes\\$env:EXT\" -ErrorAction SilentlyContinue | Select-Object -ExpandProperty '(default)' -ErrorAction SilentlyContinue" ]) .output(); @@ -208,12 +206,10 @@ impl DoctorContext { println!(" Repairing user file associations..."); for ext in &extensions { let _ = std::process::Command::new("powershell") + .env("EXT", ext) .args([ "-Command", - &format!( - "New-Item -Path 'HKCU:\\Software\\Classes\\{}' -Force -ErrorAction SilentlyContinue; Set-Item -Path 'HKCU:\\Software\\Classes\\{}' -Value 'TechScript.File'", - ext, ext - ) + "New-Item -Path \"HKCU:\\Software\\Classes\\$env:EXT\" -Force -ErrorAction SilentlyContinue; Set-Item -Path \"HKCU:\\Software\\Classes\\$env:EXT\" -Value 'TechScript.File'" ]) .output(); }