• Marc Cornellà's avatar
    fix(plugins): fix potential command injection in `rand-quote` and `hitokoto` · 72928432
    Marc Cornellà authored
    The `rand-quote` plugin uses quotationspage.com and prints part of its content to the
    shell without sanitization, which could trigger command injection. There is no evidence
    that this has been exploited, but this commit removes all possibility for exploit.
    
    Similarly, the `hitokoto` plugin uses the hitokoto.cn website to print quotes to the
    shell, also without sanitization. Furthermore, there is also no evidence that this has
    been exploited, but with this change it is now impossible.
    72928432
Name
Last commit
Last update
.github Loading commit data...
cache Loading commit data...
custom Loading commit data...
lib Loading commit data...
log Loading commit data...
plugins Loading commit data...
templates Loading commit data...
themes Loading commit data...
tools Loading commit data...
.editorconfig Loading commit data...
.gitignore Loading commit data...
.gitpod.Dockerfile Loading commit data...
.gitpod.yml Loading commit data...
CODE_OF_CONDUCT.md Loading commit data...
CONTRIBUTING.md Loading commit data...
LICENSE.txt Loading commit data...
README.md Loading commit data...
SECURITY.md Loading commit data...
oh-my-zsh.sh Loading commit data...