-
Notifications
You must be signed in to change notification settings - Fork 64
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: validate urls before opening them [AEM-04] #2257
Comments
related: sindresorhus/open#323 |
tripodsan
added a commit
that referenced
this issue
Oct 18, 2023
tripodsan
added a commit
that referenced
this issue
Oct 18, 2023
🎉 This issue has been resolved in version 15.0.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Description
Follow up to #2149 from remediation:
We noted that such URL‐encoding was not applied for the
hlx up
orhlx import
command. It is therefore still possible to inject OS commands. The following commands will runcalc.exe
on the host machine:Expected behavior
OS command injection prevented
The text was updated successfully, but these errors were encountered: