Skip to content

fix: sanitize shell/subprocess call in extractSlotComponents.js - #1229

Open
anupamme wants to merge 2 commits into
PrismarineJS:masterfrom
anupamme:fix-repo-minecraft-data-command-injection-extract-slot-components
Open

anupamme wants to merge 2 commits into
PrismarineJS:masterfrom
anupamme:fix-repo-minecraft-data-command-injection-extract-slot-components

Conversation

@anupamme

Copy link
Copy Markdown
Contributor

Summary

Fix high severity security issue in tools/js/extractSlotComponents.js.

Vulnerability

Field Value
ID V-002
Severity HIGH
Scanner multi_agent_ai
Rule V-002
File tools/js/extractSlotComponents.js:3
Assessment Likely exploitable
CWE CWE-78

Description: The version argument is used without validation in a shell command string passed to cp.execSync() for git clone, enabling command injection via shell metacharacters.

Evidence

Exploitation scenario: Execute: node tools/js/extractSlotComponents.js '1.21; rm -rf ~'.

Scanner confirmation: multi_agent_ai rule V-002 flagged this pattern.

Changes

  • tools/js/extractSlotComponents.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security

@rom1504 rom1504 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Astra agent review — AI-generated, not manually written by the maintainer.

At a109e14, this conservative CLI hardening looks ready for maintainer merge review. The version allowlist runs before the shell command, preserves ordinary release/snapshot labels, and excludes shell metacharacters. The demonstrated boundary is a maintainer-supplied command-line argument; I found no evidence here for the description’s broader network-library vulnerability claim. No subprocess or repository mutation was executed during review.

Skills used: prismarine-review checked the current revision and discussion; prismarine-protocol-data-review checked the version-selected producer/consumer contract; prismarine-architecture-review checked package ownership and integration scope.

Use execFileSync with an argument array instead of execSync's shell
string so no part of the git clone command is parsed by a shell, and
keep the version allowlist regex as defense-in-depth. Adds a
regression test covering shell metacharacter rejection and ordinary
dotted version labels.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@anupamme

anupamme commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Review comments addressed. Pls review.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants