fzf-tmux: validate attached layout size value

Attached option form (e.g. -l50) captured size via ${arg:2} with no
validation, unlike the separate-argument form. For -l/-u the value
reached $((...)) arithmetic, where a[$(cmd)] runs cmd during option
parsing, before any tmux check. Same value was also expanded unquoted
into `tmux popup ... $opt`, allowing tmux flag injection.

Apply the separate-form regex to the attached form too. Rejects the
array-subscript payload and space-bearing geometry values that enabled
flag injection.

Reported-by: sb24CK (https://github.com/sb24CK)
This commit is contained in:
Junegunn Choi committed 2026-10-11 11:27:05 +09:00
1 parent d8aeec3058
commit f126ff2954
2 files changed
+3

No files matched your search

+1
View File
@@ -78,6 +78,7 @@ while [[ $# -gt 0 ]]; do
fi
if [[ ${#arg} -gt 2 ]]; then
size="${arg:2}"
[[ $size =~ ^[0-9%,]+$ || $size =~ ^[A-Z]$ ]] || continue
else
if [[ $1 =~ ^[0-9%,]+$ ]] || [[ $1 =~ ^[A-Z]$ ]]; then
size="$1"