Skip to content

idd-all Phase 5: PR body heredoc 改 quoted (預防未來 RCE) #7

Description

@kiki830621

Problem

From verification of #1 (P3 finding 17 — security reviewer):
Phase 5 PR body 用 unquoted heredoc:

PR_BODY=$(cat <<EOF
Refs #${N}

## Summary
{從 issue title + diagnosis 的 Strategy 摘要}
...
EOF
)

<<EOF(非 <<'EOF')讓 shell 對內容做 variable expansion + command substitution。目前 ${TITLE} / {...} placeholder 是註解性質沒實際插入,但若未來 maintainer 真的把 ${TITLE} 寫進 body,issue title 含 backticks (`rm -rf /`) 或 $(...) 就會 RCE。

Pre-existing — <<EOF 在 v2.40.0 之前就這樣寫;#1 verify 順手 catch。

Type

fix / security defensive (future-proofing)

Why P3 (latent)

  • 目前 placeholder 是字面 {...} 不是 ${...},沒實際 expansion
  • 但 placeholder 用法看起來像 template,maintainer 容易誤以為可以直接塞 ${TITLE}
  • 用 quoted heredoc 是純 win-win:預防誤用 + 標示 "這裡的 $ 是字面"

Recommendation

改成 quoted heredoc,然後在外面用 printf 或 envsubst 做 controlled substitution:

TEMPLATE=$(cat <<'EOF'
Refs #__N__

## Summary
__SUMMARY__

## Verification
6-AI cross-model verification PASS。詳見 issue #__N__ 的 Verify comment。
...
EOF
)

PR_BODY=$(echo "$TEMPLATE" | sed -e "s/__N__/$N/g" -e "s/__SUMMARY__/$(escape_sed "$SUMMARY")/g")

或繼續用 expansion-allowed heredoc 但加註釋警告未來 maintainer:

# WARNING: <<EOF (not <<'EOF') — variable expansion happens.
# DO NOT insert untrusted strings (e.g. issue titles) without sanitization.
PR_BODY=$(cat <<EOF
...
EOF
)

Source

Related: #1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions