MCPcopy Create free account
hub / github.com/FlowiseAI/Flowise / validateCommandInjection

Function validateCommandInjection

packages/components/nodes/tools/MCP/core.ts:262–285  ·  view source on GitHub ↗
(args: string[])

Source from the content-addressed store, hash-verified

260}
261
262export const validateCommandInjection = (args: string[]): void => {
263 const dangerousPatterns = [
264 // Shell metacharacters
265 /[;&|`$(){}[\]<>]/,
266 // Command chaining
267 /&&|\|\||;;/,
268 // Redirections
269 />>|<<|>/,
270 // Backticks and command substitution
271 /`|\$\(/,
272 // Process substitution
273 /<\(|>\(/
274 ]
275
276 for (const arg of args) {
277 if (typeof arg !== 'string') continue
278
279 for (const pattern of dangerousPatterns) {
280 if (pattern.test(arg)) {
281 throw new Error(`Argument contains potentially dangerous characters: "${arg}"`)
282 }
283 }
284 }
285}
286
287/**
288 * Validates user-supplied env vars against the operator-controlled allow-list in

Callers 2

core.test.tsFile · 0.90
validateMCPServerConfigFunction · 0.85

Calls 1

testMethod · 0.80

Tested by

no test coverage detected