Run the tag address in a sandbox in the preview too

A preview runs as soon as an entry is highlighted, so a crafted tags file did
not even need to be selected to get a shell command out of
'vim -c "silent {excmd}"'.

The preview Vim starts with '-u NONE' and exits right after, so the sandbox
alone is enough there; nothing it still permits outlives the process.
This commit is contained in:
Junegunn Choi
2026-09-27 23:20:27 +09:00
parent c228c70ee3
commit 9705771895
+4 -1
View File
@@ -30,9 +30,12 @@ else
exit 1
fi
# The address comes from a tags file, which can be untrusted, and a preview
# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is,
# so that it cannot run a shell command or touch a file
CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \
-c "set nomagic" \
-c "silent ${EXCMD}" \
-c "silent sandbox ${EXCMD}" \
-c 'let l=line(".") | new | put =l | print | qa!')" || exit
START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"