Skip to content

v1.4.461

Choose a tag to compare

@github-actions github-actions released this 28 Jul 14:51

Changes

PR #2152 by AUTHENSOR: fix: shell-escape extension values to prevent command injection

  • Fix: Shell-escape extension values to prevent command injection in the extension executor, which previously ran commands via sh -c with unescaped, user-controlled values interpolated into the command string. All user-controlled values are now wrapped in single quotes with embedded-single-quote escaping prior to interpolation, ensuring the shell treats them as literal arguments. A regression test (ShellInjectionBlocked) has been added to verify that malicious input (e.g., hello; touch /marker) does not execute unintended shell commands.