From 97057718951651e041d18a6ab4a89f9ecabcd8f3 Mon Sep 17 00:00:00 2001 From: Junegunn Choi Date: Sun, 27 Sep 2026 23:20:27 +0900 Subject: [PATCH] Run the tag address in a sandbox in the preview too A preview runs as soon as an entry is highlighted, so a crafted tags file did not even need to be selected to get a shell command out of 'vim -c "silent {excmd}"'. The preview Vim starts with '-u NONE' and exits right after, so the sandbox alone is enough there; nothing it still permits outlives the process. --- bin/tagpreview.sh | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/bin/tagpreview.sh b/bin/tagpreview.sh index 48ee539..01bfa30 100755 --- a/bin/tagpreview.sh +++ b/bin/tagpreview.sh @@ -30,9 +30,12 @@ else exit 1 fi +# The address comes from a tags file, which can be untrusted, and a preview +# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, +# so that it cannot run a shell command or touch a file CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \ -c "set nomagic" \ - -c "silent ${EXCMD}" \ + -c "silent sandbox ${EXCMD}" \ -c 'let l=line(".") | new | put =l | print | qa!')" || exit START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"