a263cdac9c15de4003d3289a53cad1d19c8cfb3f

Author
Marc Cornellà <hello@mcornella.com>
Committer
Marc Cornellà <hello@mcornella.com>
Date

Message

fix(lib): fix potential command injection in `title` and `spectrum` functions

The `title` function unsafely prints its input without sanitization, which if used
with custom user code that calls it, it could trigger command injection.

The `spectrum_ls` and `spectrum_bls` could similarly be exploited if a variable is
changed in the user's shell environment with a carefully crafted value. This is
highly unlikely to occur (and if possible, other methods would be used instead),
but with this change the exploit of these two functions is now impossible.

Diff

 1diff --git a/lib/spectrum.zsh b/lib/spectrum.zsh
 2index d5c22a8c547e84830416474544caefd106569fe0..97f5c360a05885b12bb99d5b5b279b7127345ea5 100644
 3--- a/lib/spectrum.zsh
 4+++ b/lib/spectrum.zsh
 5@@ -20,16 +20,18 @@ done
 6 
 7 # Show all 256 colors with color number
 8 function spectrum_ls() {
 9+  setopt localoptions nopromptsubst
10   local ZSH_SPECTRUM_TEXT=${ZSH_SPECTRUM_TEXT:-Arma virumque cano Troiae qui primus ab oris}
11   for code in {000..255}; do
12-    print -P -- "$code: $FG[$code]$ZSH_SPECTRUM_TEXT%{$reset_color%}"
13+    print -P -- "$code: ${FG[$code]}${ZSH_SPECTRUM_TEXT}%{$reset_color%}"
14   done
15 }
16 
17 # Show all 256 colors where the background is set to specific color
18 function spectrum_bls() {
19+  setopt localoptions nopromptsubst
20   local ZSH_SPECTRUM_TEXT=${ZSH_SPECTRUM_TEXT:-Arma virumque cano Troiae qui primus ab oris}
21   for code in {000..255}; do
22-    print -P -- "$code: $BG[$code]$ZSH_SPECTRUM_TEXT%{$reset_color%}"
23+    print -P -- "$code: ${BG[$code]}${ZSH_SPECTRUM_TEXT}%{$reset_color%}"
24   done
25 }
26diff --git a/lib/termsupport.zsh b/lib/termsupport.zsh
27index ef0d78895b019888bb01e35751a18ea72f03f8ed..49f64400ba83dc04979d72d66d9927d76930a4f5 100644
28--- a/lib/termsupport.zsh
29+++ b/lib/termsupport.zsh
30@@ -7,8 +7,7 @@
31 # (In screen, only short_tab_title is used)
32 # Limited support for Apple Terminal (Terminal can't set window and tab separately)
33 function title {
34-  emulate -L zsh
35-  setopt prompt_subst
36+  setopt localoptions nopromptsubst
37 
38   # Don't set the title if inside emacs, unless using vterm
39   [[ -n "$INSIDE_EMACS" && "$INSIDE_EMACS" != vterm ]] && return
40@@ -48,13 +47,13 @@ fi
41 
42 # Runs before showing the prompt
43 function omz_termsupport_precmd {
44-  [[ "${DISABLE_AUTO_TITLE:-}" == true ]] && return
45-  title $ZSH_THEME_TERM_TAB_TITLE_IDLE $ZSH_THEME_TERM_TITLE_IDLE
46+  [[ "${DISABLE_AUTO_TITLE:-}" != true ]] || return
47+  title "$ZSH_THEME_TERM_TAB_TITLE_IDLE" "$ZSH_THEME_TERM_TITLE_IDLE"
48 }
49 
50 # Runs before executing the command
51 function omz_termsupport_preexec {
52-  [[ "${DISABLE_AUTO_TITLE:-}" == true ]] && return
53+  [[ "${DISABLE_AUTO_TITLE:-}" != true ]] || return
54 
55   emulate -L zsh
56   setopt extended_glob
57@@ -97,10 +96,10 @@ function omz_termsupport_preexec {
58   fi
59 
60   # cmd name only, or if this is sudo or ssh, the next cmd
61-  local CMD=${1[(wr)^(*=*|sudo|ssh|mosh|rake|-*)]:gs/%/%%}
62+  local CMD="${1[(wr)^(*=*|sudo|ssh|mosh|rake|-*)]:gs/%/%%}"
63   local LINE="${2:gs/%/%%}"
64 
65-  title '$CMD' '%100>...>$LINE%<<'
66+  title "$CMD" "%100>...>${LINE}%<<"
67 }
68 
69 autoload -Uz add-zsh-hook