Vulnerability in BaseAI project
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 25/100
- Issue 類型
- 缺陷
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 技術堆疊
- typescript
研究方向
Start at the Wrangler CLI path for wrangler pages deploy, focusing on handling of the --commit-hash parameter during deployment. Trace where that value reaches the shell command, then add validation or sanitization and regression coverage demonstrating that command injection is not possible.
由索引模型根據 Issue 內容生成。
描述
Description
While working on BaseAI project, I identified a security vulnerability in the Wrangler CLI during the deployment process. The vulnerability exists in the wrangler pages deploy command and is related to improper handling of the --commit-hash parameter. This parameter is directly passed into a shell command without proper validation or sanitization, which leads to a command injection vulnerability (CWE-78).
Code example
No response
Additional context
No response
- 主要語言
- TypeScript
- 星號
- 1.3k
- 分支
- 112
- PR 合併指標
- 30 天內沒有已合併 PR
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
CommandCodeAI/BaseAI 的其他 Issue
-
難度 3/5 1-2 天 新手友好度 35/100
CommandCodeAI/BaseAI#177 ·
-
難度 2/5 1-3 小時 新手友好度 35/100
CommandCodeAI/BaseAI#155 · 3 則留言 · 1 個 reaction ·
-
難度 2/5 1-3 小時 新手友好度 55/100
CommandCodeAI/BaseAI#154 ·
-
Unable to deploy 未關閉
難度 4/5 3-5 天 新手友好度 25/100
CommandCodeAI/BaseAI#153 ·
-
難度 1/5 1 小時以內 新手友好度 45/100
CommandCodeAI/BaseAI#151 · 1 則留言 ·
查看 CommandCodeAI/BaseAI 的全部 Issue
相似的 Issue
-
Type/Bug
難度 2/5 1-3 小時 新手友好度 78/100
OpenNSW/nsw-srilanka#497 ·
-
難度 2/5 1-3 小時 新手友好度 72/100
0xMiden/bridge-portal#132 ·
-
react-doctor severity:warning tech-debt
難度 1/5 1 小時以內 新手友好度 88/100
digidem/comapeo-cloud-app#403 ·
-
難度 2/5 1-3 小時 新手友好度 72/100
-
難度 2/5 1-3 小時 新手友好度 78/100