mirror of
https://github.com/junegunn/fzf.git
synced 2026-10-11 23:50:20 +08:00
fzf-tmux: validate attached layout size value
Attached option form (e.g. -l50) captured size via ${arg:2} with no
validation, unlike the separate-argument form. For -l/-u the value
reached $((...)) arithmetic, where a[$(cmd)] runs cmd during option
parsing, before any tmux check. Same value was also expanded unquoted
into `tmux popup ... $opt`, allowing tmux flag injection.
Apply the separate-form regex to the attached form too. Rejects the
array-subscript payload and space-bearing geometry values that enabled
flag injection.
Reported-by: sb24CK (https://github.com/sb24CK)
This commit is contained in:
2 files changed
+3
No files matched your search
@@ -11,6 +11,8 @@ CHANGELOG
|
||||
- A `focus` binding that runs `reload` now triggers itself again after each reload, unless `--id-nth` is set and the key does not change
|
||||
- Fixed `--popup` unzooming the window when opened over a zoomed pane on tmux 3.8 or above (#4927, junegunn/fzf.vim#1625)
|
||||
- On tmux 3.7, the window is still unzoomed, as tmux 3.7b crashes when a floating pane is created over a zoomed window
|
||||
- Security fixes
|
||||
- fzf-tmux no longer evaluates an attached layout size (e.g. `-l50`) via bash arithmetic, which could run commands or inject tmux flags (GHSA-w6x2-f5m4-xw82)
|
||||
|
||||
0.74.4
|
||||
------
|
||||
|
||||
@@ -78,6 +78,7 @@ while [[ $# -gt 0 ]]; do
|
||||
fi
|
||||
if [[ ${#arg} -gt 2 ]]; then
|
||||
size="${arg:2}"
|
||||
[[ $size =~ ^[0-9%,]+$ || $size =~ ^[A-Z]$ ]] || continue
|
||||
else
|
||||
if [[ $1 =~ ^[0-9%,]+$ ]] || [[ $1 =~ ^[A-Z]$ ]]; then
|
||||
size="$1"
|
||||
|
||||
Reference in new issue
Block a user