Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

[security] Hover over punctuation executes the first expression in the file (document.getText(undefined) → whole document → eval in globalenv)

Offen
#1,802 3 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
55/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
r, typescript, vscode
Bereich
security, tooling

Rechercherichtung

Start with the hover-provider logic in dist/extension.js and the sess::handle_hover() path described in the report. Reproduce the issue using test.R with rm(list = ls()) and hover over punctuation, then verify that punctuation no longer sends the whole document for evaluation and that multi-expression input is rejected defensively.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

bug confirmed

Environment: vscode-R 3.0.1, sess 3.0.1, R 4.6.1, radian, Linux (remote).

Summary: Hovering the mouse over any punctuation character in an .R file sends the entire document to sess::handle_hover, which evaluates its first top-level expression in the global environment. For the very common file header rm(list = ls()), this silently deletes the user's whole workspace with no console output.

Cause: In the sess hover provider (dist/extension.js):
let r = t.getWordRangeAtPosition(n); const a = /([a-zA-Z0-9._$@ ])+(?<![@$])/; r = t.getWordRangeAtPosition(n, a)?.with({ end: r?.end }); let s = t.getText(r); // r may be undefined -> returns whole document await Zi({ method: "hover", params: { expr: s } });

The regex character class [a-zA-Z0-9._$@ ] does not match #, ", (, ,, |, =, etc. When it fails, r is undefined and document.getText(undefined) returns the full document per the VS Code API.

sess::handle_hover() then does:
expr <- parse(text = expr_str, keep.source = FALSE)[[1]] obj <- eval(expr, .GlobalEnv)
so the first parsed expression of the file is executed. This is arbitrary code execution triggered by mouse movement — unlink(), dbExecute(), system() etc. would run just as readily.

Repro:

Create test.R starting with rm(list = ls()).
In R: a <- 1; b <- 2.
Hover over the # of any comment (not over a word).
ls() → character(0).
Suggested fix: bail out when the range is undefined, and defensively reject multi-expression input in handle_hover/handle_complete:
if (!r) return null;
Note: hovering over letters behaves correctly, which is why this is easy to miss.

Vorherrschende Sprache
TypeScript
Sterne
1.2k
Forks
139
Ø Merge
19 Std. 50 Min.
Gemergte PRs (30 T.)
27

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus REditorSupport/vscode-R

Alle Issues in REditorSupport/vscode-R

Ähnliche Issues

Weitere Issues zu TypeScript

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.