Command Injection
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 25/100
- Tipo di issue
- Bug
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- macos, swift
- Ambito
- desktop-dev, security
Direzione di ricerca
Inizia tracciando il parametro filepath attraverso gli entry point per la gestione dei file di riferimento e della modalità agente descritti nell’issue, quindi riproduci il comportamento usando il filename fornito in un progetto di test sicuro. Il lavoro è completato quando un filename malevolo non può più causare l’esecuzione di comandi all’apertura o all’utilizzo del file referenziato tramite Copilot.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
An attacker can execute arbitrary commands on the user's machine.
Version: 0.43.0
Technical Impact
An attacker can create a project containing a maliciously crafted file name. If a user opens the project in Xcode and interacts with the file using the Copilot extension, the command will be executed on the system.
Code Review
The filepath parameter is used directly while opening the reference file in the code, leading to command injection.
Steps to reproduce
- Create a file with the following payload
main.swift";cat>xxd -r -p <<< 2f746d702f68657861616161;".swift
- The file will be automatically attached to the Xcode chat editor.
- Send any message to interact with Copilot.
- Click on the referenced file. Command mentioned in the filename will be executed.
I reported this to GitHub Security in version 0.31.0 but did not receive a response. I also reported the issue to the developer of the intitni repository, and they fixed it in the below commit
https://github.com/intitni/CopilotForXcode/commit/9340275e615197fd7cd3ee8b2ed992893119b38d
Now I see that the vulnerable code is also used for agent mode. Since the issue is already public, I am sharing the details.
- Lingua principale
- Swift
- Stelle
- 6.3k
- Fork
- 2k
- Merge medio
- 3g 21h
- PR unite (30g)
- 2
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/CopilotForXcode
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
github/CopilotForXcode#181 · 2 reazioni ·
-
Add ability to attach Copilot window only to Xcode projects/workspaces, ignoring standalone files Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
github/CopilotForXcode#945 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 35/100
github/CopilotForXcode#943 ·
-
Luisgerardomartinezlara Aperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 10/100
github/CopilotForXcode#936 · 2 commenti ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 10/100
github/CopilotForXcode#934 ·
Tutte le issue di github/CopilotForXcode
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
bitcoindevkit/bdk-ffi#1125 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
manaflow-ai/cmux#13417 ·
-
triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
ionic-team/capacitor#8616 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
paritytech/host-rust-core#868 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
Cocoanetics/SwiftMail#238 · 1 commento ·