(args: string[])
| 260 | } |
| 261 | |
| 262 | export const validateCommandInjection = (args: string[]): void => { |
| 263 | const dangerousPatterns = [ |
| 264 | // Shell metacharacters |
| 265 | /[;&|`$(){}[\]<>]/, |
| 266 | // Command chaining |
| 267 | /&&|\|\||;;/, |
| 268 | // Redirections |
| 269 | />>|<<|>/, |
| 270 | // Backticks and command substitution |
| 271 | /`|\$\(/, |
| 272 | // Process substitution |
| 273 | /<\(|>\(/ |
| 274 | ] |
| 275 | |
| 276 | for (const arg of args) { |
| 277 | if (typeof arg !== 'string') continue |
| 278 | |
| 279 | for (const pattern of dangerousPatterns) { |
| 280 | if (pattern.test(arg)) { |
| 281 | throw new Error(`Argument contains potentially dangerous characters: "${arg}"`) |
| 282 | } |
| 283 | } |
| 284 | } |
| 285 | } |
| 286 | |
| 287 | /** |
| 288 | * Validates user-supplied env vars against the operator-controlled allow-list in |
no test coverage detected