Security/Bug: Go server leaks auth_token to ps and leaves zombie processes
@jakubbortlik ci sta già lavorando.
Dal 22/9/2026.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 46/100
Direzione di ricerca
Inizia con :h gitlab.nvim.troubleshooting, quindi individua l'avvio del server tramite vim.system(), la gestione della configurazione Go e la gestione del ciclo di vita di VimLeavePre. Il report non indica file sorgente né test e lascia incompleta la riproduzione. Il lavoro è completato quando l'autenticazione continua a funzionare senza esporre il token negli argomenti del processo e i processi del server non rimangono dopo l'uscita di Neovim, incluse le uscite rapide o forzate segnalate.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Prerequsities
- I'm on the latest version of the plugin
- I've installed the required dependencies
- I've run
:h gitlab.nvim.troubleshootingand followed the steps there
Setup Configuration and Environment
NVIM v0.12.4
Build type: Release
LuaJIT 2.1.1784580905
Vim versions: 8.1, 8.2, 9.0, 9.1, 9.2
system vimrc file: "$VIM/sysinit.vim"
fall-back for $VIM: "/usr/local/Cellar/neovim/0.12.4/share/nvim"
Bug Description
Currently, gitlab.nvim passes its configuration JSON (which contains the auth_token) directly
to the Go server binary via a command-line argument when calling vim.system().
Because command-line arguments are globally visible on UNIX systems via ps or pgrep, any user
on the machine can easily read the GitLab API token just by listing running processes.
Additionally, if Neovim is closed forcefully or quickly (e.g. via scripts or aliases), the Go
server processes aren't killed and become orphaned zombies running in the background. Because
they pile up, it becomes very easy to accidentally spot the leaked token in pgrep -fl nvim outputs.
Reproduction Steps
- Check out the feature branch
- Open Neovim
- ...
Screenshots
➜ pgrep -fl nvim
2080 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"gitlab_url":"https://xxxxxxxxxxxxxxx.com","connection_settings":{"insecure":false,"proxy":"","remote":"origin"},"debug":{"response":false,"request":false,"gitlab_request":false,"gitlab_response":false},"port":54232,"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx"}
21519 nvim . .
21544 nvim --embed . .
66859 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"chosen_mr_iid":4143,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com","debug":{"request":false,"gitlab_request":false,"gitlab_response":false,"response":false},"connection_settings":{"proxy":"","remote":"origin","insecure":false},"port":51887}
83060 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"debug":{"gitlab_request":false,"gitlab_response":false,"response":false,"request":false},"connection_settings":{"remote":"origin","proxy":"","insecure":false},"port":0,"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com"}
84503 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"debug":{"gitlab_request":false,"gitlab_response":false,"response":false,"request":false},"connection_settings":{"remote":"origin","proxy":"","insecure":false},"port":0,"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com"}
91585 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","port":0,"gitlab_url":"https://xxxxxxxxxxxxxxx.com","debug":{"request":false,"gitlab_request":false,"gitlab_response":false,"response":false},"connection_settings":{"insecure":false,"proxy":"","remote":"origin"},"auth_token":"xxxxxxxxxxxxxxxxx","chosen_mr_iid":0}
95389 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","debug":{"gitlab_response":false,"response":false,"request":false,"gitlab_request":false},"gitlab_url":"https://xxxxxxxxxxxxxxx.com","connection_settings":{"proxy":"","insecure":false,"remote":"origin"},"port":0}
97335 /Users/xxxxxxx/.local/share/nvim/gitlab.nvim/bin/server {"debug":{"response":false,"request":false,"gitlab_request":false,"gitlab_response":false},"chosen_mr_iid":0,"log_path":"/Users/xxxxxxx/.cache/nvim/gitlab.nvim.log","auth_token":"xxxxxxxxxxxxxxxxx","gitlab_url":"https://xxxxxxxxxxxxxxx.com","connection_settings":{"insecure":false,"remote":"origin","proxy":""},"port":0}
Suggested Fix
The configuration JSON (or at least the auth_token) should be passed to the Go server via stdin
or as an environment variable, rather than as a command-line argument. Additionally, it would
be great if the plugin ensured the server process is killed properly upon VimLeavePre.
- Lingua principale
- Lua
- Stelle
- 401
- Fork
- 64
- Merge medio
- 7h 17m
- PR unite (30g)
- 4
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di harrisoncramer/gitlab.nvim
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
harrisoncramer/gitlab.nvim#585 · 1 commento ·
-
feature request
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
harrisoncramer/gitlab.nvim#516 · 1 commento ·
-
Oauth Login the pluginForse di nuovo libera @vamshi567bh l’ha presa 254 giorni fa e non c’è nessuna pull request aperta. Apertafeature request
harrisoncramer/gitlab.nvim#515 · 2 commenti · 1 assegnatario ·
-
toggle_discussions() doesn't open new window - draft_notes error 404Forse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
harrisoncramer/gitlab.nvim#507 · 1 commento ·
-
feature request
Difficoltà 3/5 1-2 giorni Idoneità per principianti 56/100
harrisoncramer/gitlab.nvim#505 · 6 commenti ·
Tutte le issue di harrisoncramer/gitlab.nvim
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
jellyfin/jellyfin-mpv-shim#800 ·
I maintainer di solito rispondono entro 1 giorno
-
agent-research-finding bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
jordansmall/nixvim-config#99 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
xmake-io/xmake#7822 · 3 commenti ·
I maintainer di solito rispondono entro 2 giorni
-
omarchy-menu-keybindings lua bind scan spins at 100% CPU when user config iterates a mocked hl APIAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
omacom/omarchy#14302 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
BUG
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
linuxmint/cinnamon-spices-applets#9091 ·
I maintainer di solito rispondono entro 1 giorno