mirror of
https://github.com/junegunn/fzf.vim.git
synced 2026-09-30 15:42:23 +08:00
Run the tag address in a sandbox in the preview too
A preview runs as soon as an entry is highlighted, so a crafted tags file did
not even need to be selected to get a shell command out of
'vim -c "silent {excmd}"'.
The preview Vim starts with '-u NONE' and exits right after, so the sandbox
alone is enough there; nothing it still permits outlives the process.
This commit is contained in:
+4
-1
@@ -30,9 +30,12 @@ else
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# The address comes from a tags file, which can be untrusted, and a preview
|
||||
# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is,
|
||||
# so that it cannot run a shell command or touch a file
|
||||
CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \
|
||||
-c "set nomagic" \
|
||||
-c "silent ${EXCMD}" \
|
||||
-c "silent sandbox ${EXCMD}" \
|
||||
-c 'let l=line(".") | new | put =l | print | qa!')" || exit
|
||||
|
||||
START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"
|
||||
|
||||
Reference in New Issue
Block a user