github / github/CopilotForXcode

Command Injection

オープン
#548 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Swift
スター
6.3k
フォーク
2k
平均マージ
2分
マージ済み PR(30日)
2

説明

**Description**

An attacker can execute arbitrary commands on the user's machine.

Version: 0.43.0

**Technical Impact**

An attacker can create a project containing a maliciously crafted file name. If a user opens the project in Xcode and interacts with the file using the Copilot extension, the command will be executed on the system.

Code Review

Image

The `filepath` parameter is used directly while opening the reference file in the code, leading to command injection.

Steps to reproduce

1. Create a file with the following payload

`main.swift";cat>xxd -r -p <<< 2f746d702f68657861616161;".swift`

Image

1. The file will be automatically attached to the Xcode chat editor.
2. Send any message to interact with Copilot.
3. Click on the referenced file. Command mentioned in the filename will be executed.

Image

I reported this to GitHub Security in version 0.31.0 but did not receive a response. I also reported the issue to the developer of the intitni repository, and they fixed it in the below commit

Image

https://github.com/intitni/CopilotForXcode/commit/9340275e615197fd7cd3ee8b2ed992893119b38d

Now I see that the vulnerable code is also used for agent mode. Since the issue is already public, I am sharing the details.

Image

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。