Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[security] Hover over punctuation executes the first expression in the file (document.getText(undefined) → whole document → eval in globalenv)

Abierto
#1,802 3 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
55/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
r, typescript, vscode
Área
security, tooling

Línea de trabajo

Start with the hover-provider logic in dist/extension.js and the sess::handle_hover() path described in the report. Reproduce the issue using test.R with rm(list = ls()) and hover over punctuation, then verify that punctuation no longer sends the whole document for evaluation and that multi-expression input is rejected defensively.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug confirmed

Environment: vscode-R 3.0.1, sess 3.0.1, R 4.6.1, radian, Linux (remote).

Summary: Hovering the mouse over any punctuation character in an .R file sends the entire document to sess::handle_hover, which evaluates its first top-level expression in the global environment. For the very common file header rm(list = ls()), this silently deletes the user's whole workspace with no console output.

Cause: In the sess hover provider (dist/extension.js):
let r = t.getWordRangeAtPosition(n); const a = /([a-zA-Z0-9._$@ ])+(?<![@$])/; r = t.getWordRangeAtPosition(n, a)?.with({ end: r?.end }); let s = t.getText(r); // r may be undefined -> returns whole document await Zi({ method: "hover", params: { expr: s } });

The regex character class [a-zA-Z0-9._$@ ] does not match #, ", (, ,, |, =, etc. When it fails, r is undefined and document.getText(undefined) returns the full document per the VS Code API.

sess::handle_hover() then does:
expr <- parse(text = expr_str, keep.source = FALSE)[[1]] obj <- eval(expr, .GlobalEnv)
so the first parsed expression of the file is executed. This is arbitrary code execution triggered by mouse movement — unlink(), dbExecute(), system() etc. would run just as readily.

Repro:

Create test.R starting with rm(list = ls()).
In R: a <- 1; b <- 2.
Hover over the # of any comment (not over a word).
ls() → character(0).
Suggested fix: bail out when the range is undefined, and defensively reject multi-expression input in handle_hover/handle_complete:
if (!r) return null;
Note: hovering over letters behaves correctly, which is why this is easy to miss.

Lenguaje dominante
TypeScript
Estrellas
1.2k
Forks
139
Merge medio
19 h 50 min
PR fusionados (30 d)
27

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de REditorSupport/vscode-R

Todos los issues de REditorSupport/vscode-R

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.