Skip to content

Shell injection via CLI_ARGS interpolated into sh -c command templates #19

@consigcody94

Description

@consigcody94

Found via code audit. src/nix-dispatcher/src/commands.rs:105-114. task_interpolator.rs does raw string .replace of {{.CLI_ARGS}} with unsanitized user input fed to sh -c.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions