[MEDIUM] Preserve substituted browser URIs as one argument - #169
Open
OskarEichler wants to merge 1 commit into
Open
[MEDIUM] Preserve substituted browser URIs as one argument#169OskarEichler wants to merge 1 commit into
OskarEichler wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
BROWSERcommand templates before substituting the requested URISecurity impact
Severity: MEDIUM.
When
BROWSERcontains a%splaceholder, Launchy currently substitutes the URI beforeShellwords.shellsplit. An attacker-controlled URI can therefore become additional browser arguments; quote characters can also invalidate the command. The exact impact depends on the selected browser and its supported flags.This is argument injection into the configured browser, not shell-command injection:
ChildProcessstill receives a discrete argv and does not invoke a shell.Reproduction
With
BROWSER=/usr/bin/audit-browser --new-tab '%s', the baseline turns:into four argv elements after the executable. A URI containing a single quote instead raises
ArgumentErrorduring shell parsing. The candidate produces exactly three elements in both cases: executable, configured flag, and the complete URI.Verification
mainand passes for ordinary, space-containing, and quote-containing URIs on this branchgit diff --checkpassesNo repository tests or dependency files were changed.
Compatibility and limitations
%sexample retains its exact command string.%s, including the normal platform browser commands, are unchanged.BROWSERtemplate syntax still fails as before.