From 2b6e8b2132bde62648dc12bd2bd3bfb8a3f2ea0c Mon Sep 17 00:00:00 2001 From: Junegunn Choi Date: Mon, 28 Sep 2026 00:08:50 +0900 Subject: [PATCH] Sandbox the address the same way on the Show paths They passed ':sandbox' as a modifier, which the address check makes safe today but which stops covering anything that ever slips past it. --- autoload/fzf/vim.vim | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/autoload/fzf/vim.vim b/autoload/fzf/vim.vim index f4a864b..7101ec8 100755 --- a/autoload/fzf/vim.vim +++ b/autoload/fzf/vim.vim @@ -535,11 +535,18 @@ function! s:execute_silent(cmd) endfunction " A tag address can be any Ex command, and a tags file can come from an -" untrusted source, so run it in a sandbox as a builtin tag jump does +" untrusted source, so run it in a sandbox as a builtin tag jump does. ':sandbox' +" as a modifier only covers the command up to the first '|', so hand the address +" to ':execute', which keeps all of it inside the sandbox function! s:execute_tag_address(excmd) silent keepjumps keepalt sandbox execute a:excmd endfunction +" The same, as a command for a win_execute() list +function! s:sandboxed(cmd) + return 'sandbox execute '.string(a:cmd) +endfunction + " Address of a tag, given the rest of the line after the file name. Only the " forms a tags file is meant to hold, a line number and a search pattern, " chained with ';' for '--excmd=combine' and cut at the ';"' terminator as @@ -762,7 +769,7 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort return endif let cmds = s:edit_cmds(a:winid, path) - \ + ['sandbox keepjumps '.excmd, 'normal! ^zvzz'] + \ + [s:sandboxed('keepjumps '.excmd), 'normal! ^zvzz'] elseif a:kind ==# 'btags' let parts = split(entry, "\t") if len(parts) < 3 || !bufexists(a:bufnr) @@ -773,7 +780,7 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort return endif let cmds = ['keepalt keepjumps hide buffer '.a:bufnr, - \ 'sandbox keepjumps '.excmd, 'normal! zvzz'] + \ s:sandboxed('keepjumps '.excmd), 'normal! zvzz'] elseif a:kind ==# 'marks' " A lowercase mark is local to the buffer the run started on let mark = matchstr(entry, '^\s*\zs\S')