[security] Hover over punctuation executes the first expression in the file (document.getText(undefined) → whole document → eval in globalenv)
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- r, typescript, vscode
Direzione di ricerca
Start with the hover-provider logic in dist/extension.js and the sess::handle_hover() path described in the report. Reproduce the issue using test.R with rm(list = ls()) and hover over punctuation, then verify that punctuation no longer sends the whole document for evaluation and that multi-expression input is rejected defensively.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Environment: vscode-R 3.0.1, sess 3.0.1, R 4.6.1, radian, Linux (remote).
Summary: Hovering the mouse over any punctuation character in an .R file sends the entire document to sess::handle_hover, which evaluates its first top-level expression in the global environment. For the very common file header rm(list = ls()), this silently deletes the user's whole workspace with no console output.
Cause: In the sess hover provider (dist/extension.js):
let r = t.getWordRangeAtPosition(n); const a = /([a-zA-Z0-9._$@ ])+(?<![@$])/; r = t.getWordRangeAtPosition(n, a)?.with({ end: r?.end }); let s = t.getText(r); // r may be undefined -> returns whole document await Zi({ method: "hover", params: { expr: s } });
The regex character class [a-zA-Z0-9._$@ ] does not match #, ", (, ,, |, =, etc. When it fails, r is undefined and document.getText(undefined) returns the full document per the VS Code API.
sess::handle_hover() then does:
expr <- parse(text = expr_str, keep.source = FALSE)[[1]] obj <- eval(expr, .GlobalEnv)
so the first parsed expression of the file is executed. This is arbitrary code execution triggered by mouse movement — unlink(), dbExecute(), system() etc. would run just as readily.
Repro:
Create test.R starting with rm(list = ls()).
In R: a <- 1; b <- 2.
Hover over the # of any comment (not over a word).
ls() → character(0).
Suggested fix: bail out when the range is undefined, and defensively reject multi-expression input in handle_hover/handle_complete:
if (!r) return null;
Note: hovering over letters behaves correctly, which is why this is easy to miss.
- Lingua principale
- TypeScript
- Stelle
- 1.2k
- Fork
- 145
- Merge medio
- 1g 14h
- PR unite (30g)
- 46
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di REditorSupport/vscode-R
-
(feat) Additional Arrow supportForse già presa @Fred-Wu l’ha presa 5 giorni fa. Apertaenhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
REditorSupport/vscode-R#1785 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
View() on lists shows blank pane — jquery.json-viewer.css path mismatch in 2.8.7Forse già presa @Fred-Wu l’ha presa 15 giorni fa. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
REditorSupport/vscode-R#1687 · 4 commenti · 3 reazioni ·
I maintainer di solito rispondono entro 1 giorno
-
On Windows, the first r.runSelection attaches R but does not sent the command to the terminalApertabug
Difficoltà 3/5 1-2 giorni Idoneità per principianti 52/100
REditorSupport/vscode-R#1815 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
bug confirmed
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
REditorSupport/vscode-R#1799 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 48/100
REditorSupport/vscode-R#1791 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di REditorSupport/vscode-R
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 4 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno