Repository navigation
Conversation
Automated security fix generated by OrbisAI Security
rom1504
left a comment
There was a problem hiding this comment.
Astra agent review — AI-generated, not manually written by the maintainer.
At a109e14, this conservative CLI hardening looks ready for maintainer merge review. The version allowlist runs before the shell command, preserves ordinary release/snapshot labels, and excludes shell metacharacters. The demonstrated boundary is a maintainer-supplied command-line argument; I found no evidence here for the description’s broader network-library vulnerability claim. No subprocess or repository mutation was executed during review.
Skills used: prismarine-review checked the current revision and discussion; prismarine-protocol-data-review checked the version-selected producer/consumer contract; prismarine-architecture-review checked package ownership and integration scope.
Use execFileSync with an argument array instead of execSync's shell string so no part of the git clone command is parsed by a shell, and keep the version allowlist regex as defense-in-depth. Adds a regression test covering shell metacharacter rejection and ordinary dotted version labels. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Review comments addressed. Pls review. |
Summary
Fix high severity security issue in
tools/js/extractSlotComponents.js.Vulnerability
V-002tools/js/extractSlotComponents.js:3Description: The version argument is used without validation in a shell command string passed to cp.execSync() for git clone, enabling command injection via shell metacharacters.
Evidence
Exploitation scenario: Execute:
node tools/js/extractSlotComponents.js '1.21; rm -rf ~'.Scanner confirmation: multi_agent_ai rule
V-002flagged this pattern.Changes
tools/js/extractSlotComponents.jsBehavior Preservation
The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.
Automated security fix by OrbisAI Security