Skip to content

v2.80.3 - Command Injection Security Fix

Choose a tag to compare

@fotsakir fotsakir released this 21 Jan 16:07
· 31 commits to main since this release

Security

  • Command Injection Fix - Replaced shell=True subprocess calls with safe alternatives
    • Use list arguments instead of f-strings for subprocess.run
    • Use shutil.copytree/copy2 instead of subprocess cp
    • Use subprocess with stdin pipe for mysql imports
    • Fixes 10 critical-severity CodeQL alerts
  • Upload Security - Added secure_filename for all file uploads
    • Prevents path traversal via malicious filenames

Upgrade

cd /root
wget https://github.com/fotsakir/codehero/releases/latest/download/codehero-2.80.3.zip
unzip codehero-2.80.3.zip
cd codehero
sudo ./upgrade.sh