fzf-tmux: validate attached layout size value

Attached option form (e.g. -l50) captured size via ${arg:2} with no
validation, unlike the separate-argument form. For -l/-u the value
reached $((...)) arithmetic, where a[$(cmd)] runs cmd during option
parsing, before any tmux check. Same value was also expanded unquoted
into `tmux popup ... $opt`, allowing tmux flag injection.

Apply the separate-form regex to the attached form too. Rejects the
array-subscript payload and space-bearing geometry values that enabled
flag injection.

Reported-by: sb24CK (https://github.com/sb24CK)
This commit is contained in:
Junegunn Choi committed 2026-10-11 11:27:05 +09:00
1 parent d8aeec3058
commit f126ff2954
2 files changed
+3

No files matched your search

+2
View File
@@ -11,6 +11,8 @@ CHANGELOG
- A `focus` binding that runs `reload` now triggers itself again after each reload, unless `--id-nth` is set and the key does not change
- Fixed `--popup` unzooming the window when opened over a zoomed pane on tmux 3.8 or above (#4927, junegunn/fzf.vim#1625)
- On tmux 3.7, the window is still unzoomed, as tmux 3.7b crashes when a floating pane is created over a zoomed window
- Security fixes
- fzf-tmux no longer evaluates an attached layout size (e.g. `-l50`) via bash arithmetic, which could run commands or inject tmux flags (GHSA-w6x2-f5m4-xw82)
0.74.4
------
+1
View File
@@ -78,6 +78,7 @@ while [[ $# -gt 0 ]]; do
fi
if [[ ${#arg} -gt 2 ]]; then
size="${arg:2}"
[[ $size =~ ^[0-9%,]+$ || $size =~ ^[A-Z]$ ]] || continue
else
if [[ $1 =~ ^[0-9%,]+$ ]] || [[ $1 =~ ^[A-Z]$ ]]; then
size="$1"