• Marc Cornellà's avatar
    fix(lib): fix potential command injection in `title` and `spectrum` functions · a263cdac
    Marc Cornellà authored
    The `title` function unsafely prints its input without sanitization, which if used
    with custom user code that calls it, it could trigger command injection.
    
    The `spectrum_ls` and `spectrum_bls` could similarly be exploited if a variable is
    changed in the user's shell environment with a carefully crafted value. This is
    highly unlikely to occur (and if possible, other methods would be used instead),
    but with this change the exploit of these two functions is now impossible.
    a263cdac
Name
Last commit
Last update
.github Loading commit data...
cache Loading commit data...
custom Loading commit data...
lib Loading commit data...
log Loading commit data...
plugins Loading commit data...
templates Loading commit data...
themes Loading commit data...
tools Loading commit data...
.editorconfig Loading commit data...
.gitignore Loading commit data...
.gitpod.Dockerfile Loading commit data...
.gitpod.yml Loading commit data...
CODE_OF_CONDUCT.md Loading commit data...
CONTRIBUTING.md Loading commit data...
LICENSE.txt Loading commit data...
README.md Loading commit data...
SECURITY.md Loading commit data...
oh-my-zsh.sh Loading commit data...