[security] Hover over punctuation executes the first expression in the file (document.getText(undefined) → whole document → eval in globalenv)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 55/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- r, typescript, vscode
调研方向
Start with the hover-provider logic in dist/extension.js and the sess::handle_hover() path described in the report. Reproduce the issue using test.R with rm(list = ls()) and hover over punctuation, then verify that punctuation no longer sends the whole document for evaluation and that multi-expression input is rejected defensively.
由索引模型根据 Issue 内容生成。
描述
Environment: vscode-R 3.0.1, sess 3.0.1, R 4.6.1, radian, Linux (remote).
Summary: Hovering the mouse over any punctuation character in an .R file sends the entire document to sess::handle_hover, which evaluates its first top-level expression in the global environment. For the very common file header rm(list = ls()), this silently deletes the user's whole workspace with no console output.
Cause: In the sess hover provider (dist/extension.js):
let r = t.getWordRangeAtPosition(n); const a = /([a-zA-Z0-9._$@ ])+(?<![@$])/; r = t.getWordRangeAtPosition(n, a)?.with({ end: r?.end }); let s = t.getText(r); // r may be undefined -> returns whole document await Zi({ method: "hover", params: { expr: s } });
The regex character class [a-zA-Z0-9._$@ ] does not match #, ", (, ,, |, =, etc. When it fails, r is undefined and document.getText(undefined) returns the full document per the VS Code API.
sess::handle_hover() then does:
expr <- parse(text = expr_str, keep.source = FALSE)[[1]] obj <- eval(expr, .GlobalEnv)
so the first parsed expression of the file is executed. This is arbitrary code execution triggered by mouse movement — unlink(), dbExecute(), system() etc. would run just as readily.
Repro:
Create test.R starting with rm(list = ls()).
In R: a <- 1; b <- 2.
Hover over the # of any comment (not over a word).
ls() → character(0).
Suggested fix: bail out when the range is undefined, and defensively reject multi-expression input in handle_hover/handle_complete:
if (!r) return null;
Note: hovering over letters behaves correctly, which is why this is easy to miss.
- 主要语言
- TypeScript
- 星标
- 1.2k
- 派生
- 145
- 平均合并
- 19 小时 50 分钟
- 30 天内合并 PR
- 27
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
REditorSupport/vscode-R 的其他 Issue
-
enhancement
难度 2/5 1-3 小时 新手友好度 72/100
REditorSupport/vscode-R#1785 · 2 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 84/100
REditorSupport/vscode-R#1687 · 4 条评论 · 3 个 reaction ·
维护者通常 1 天内回复
-
bug
难度 4/5 3-5 天 新手友好度 48/100
REditorSupport/vscode-R#1799 · 2 条评论 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 48/100
REditorSupport/vscode-R#1791 · 2 条评论 ·
维护者通常 1 天内回复
-
Rewrite issue templates可能已有人在做 @eitsupi 于 4 天前认领。 未关闭
REditorSupport/vscode-R#1783 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 REditorSupport/vscode-R 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
callstackincubator/rozenite#518 ·
维护者通常 1 天内回复
-
Area/Workflow Priority/Blocker Type/Bug
难度 2/5 1-3 小时 新手友好度 76/100
wso2/product-integrator#2622 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
-
area:bash bug has repro platform:macos
难度 2/5 1-3 小时 新手友好度 78/100
anthropics/claude-code#98644 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
allure-framework/allure-js#1603 ·
维护者通常 1 天内回复