mirror of
https://github.com/junegunn/fzf.vim.git
synced 2026-09-30 15:42:23 +08:00
A tags file can come from an untrusted source, and its address field can hold any Ex command, which :Tags, :BTags and their CTRL-O Show callback ran as is. - Take only a line number or a search pattern, chained with ';' for '--excmd=combine' and cut at the ';"' terminator as Vim's find_extra() does. A pattern can be left unterminated, which takes any '|' or ';' into the pattern, so it cannot chain a command either. Anything else is refused by name - Run the address in a sandbox, as builtin tag jumps do since Vim 6.0. ':sandbox' as a modifier stops at the first '|', so the address goes to ':execute', which keeps all of it inside - :BTags gains the search settings and the per-entry recovery the other two paths already had, so one failing address no longer drops the rest Close #1626