Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

[security] Hover over punctuation executes the first expression in the file (document.getText(undefined) → whole document → eval in globalenv)

未關閉
#1,802 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
55/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
r, typescript, vscode
領域
security, tooling

研究方向

Start with the hover-provider logic in dist/extension.js and the sess::handle_hover() path described in the report. Reproduce the issue using test.R with rm(list = ls()) and hover over punctuation, then verify that punctuation no longer sends the whole document for evaluation and that multi-expression input is rejected defensively.

由索引模型根據 Issue 內容生成。

描述

bug confirmed

Environment: vscode-R 3.0.1, sess 3.0.1, R 4.6.1, radian, Linux (remote).

Summary: Hovering the mouse over any punctuation character in an .R file sends the entire document to sess::handle_hover, which evaluates its first top-level expression in the global environment. For the very common file header rm(list = ls()), this silently deletes the user's whole workspace with no console output.

Cause: In the sess hover provider (dist/extension.js):
let r = t.getWordRangeAtPosition(n); const a = /([a-zA-Z0-9._$@ ])+(?<![@$])/; r = t.getWordRangeAtPosition(n, a)?.with({ end: r?.end }); let s = t.getText(r); // r may be undefined -> returns whole document await Zi({ method: "hover", params: { expr: s } });

The regex character class [a-zA-Z0-9._$@ ] does not match #, ", (, ,, |, =, etc. When it fails, r is undefined and document.getText(undefined) returns the full document per the VS Code API.

sess::handle_hover() then does:
expr <- parse(text = expr_str, keep.source = FALSE)[[1]] obj <- eval(expr, .GlobalEnv)
so the first parsed expression of the file is executed. This is arbitrary code execution triggered by mouse movement — unlink(), dbExecute(), system() etc. would run just as readily.

Repro:

Create test.R starting with rm(list = ls()).
In R: a <- 1; b <- 2.
Hover over the # of any comment (not over a word).
ls() → character(0).
Suggested fix: bail out when the range is undefined, and defensively reject multi-expression input in handle_hover/handle_complete:
if (!r) return null;
Note: hovering over letters behaves correctly, which is why this is easy to miss.

主要語言
TypeScript
星號
1.2k
分支
139
平均合併
19 小時 50 分鐘
30 天內合併 PR
27

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

REditorSupport/vscode-R 的其他 Issue

查看 REditorSupport/vscode-R 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。