Diff
1diff --git a/CHANGELOG.rst b/CHANGELOG.rst
2index f7b53afccbcc9557abd4f7c50cab49a5ffad87ca..975a8d51db41b366e23f041b8d4f648a6f90e226 100644
3--- a/CHANGELOG.rst
4+++ b/CHANGELOG.rst
5@@ -1,6 +1,10 @@
6 Changelog
7 =========
8
9+1.16.0
10+------
11+* Fix insecure activation of virtualenvs (#122)
12+
13 1.15.2
14 ------
15 * Use absolute path for ``/usr/bin/stat`` to prevent conflicts with other ``stat`` binaries. Fixes #110
16diff --git a/autoswitch_virtualenv.plugin.zsh b/autoswitch_virtualenv.plugin.zsh
17index d3ce1f513c5521b760309308071b2350745b9851..3b0ef5c08f686cfc154abee4d10a493db105f08e 100644
18--- a/autoswitch_virtualenv.plugin.zsh
19+++ b/autoswitch_virtualenv.plugin.zsh
20@@ -1,4 +1,4 @@
21-export AUTOSWITCH_VERSION="1.15.2"
22+export AUTOSWITCH_VERSION="1.16.0"
23 export AUTOSWITCH_FILE=".venv"
24
25 RED="\e[31m"
26@@ -8,6 +8,20 @@ BOLD="\e[1m"
27 NORMAL="\e[0m"
28
29
30+function _validated_source() {
31+ local target_path="$1"
32+
33+ if [[ "$target_path" == *'..'* ]]; then
34+ printf "AUTOSWITCH WARNING: "
35+ printf "target virtualenv contains invalid characters\n"
36+ printf "virtualenv activation cancelled\n"
37+ return
38+ else
39+ source "$target_path"
40+ fi
41+}
42+
43+
44 function _virtual_env_dir() {
45 local venv_name="$1"
46 local VIRTUAL_ENV_DIR="${AUTOSWITCH_VIRTUAL_ENV_DIR:-$HOME/.virtualenvs}"
47@@ -93,7 +107,9 @@ function _maybeworkon() {
48 fi
49
50 # Much faster to source the activate file directly rather than use the `workon` command
51- source "$venv_dir/bin/activate"
52+ local activate_script="$venv_dir/bin/activate"
53+
54+ _validated_source "$activate_script"
55 fi
56 }
57
58diff --git a/tests/test_maybeworkon.zunit b/tests/test_maybeworkon.zunit
59index d5fe6591f2bd9f558cb88a849e665e88ea260ccd..49ae98dd6cc304b97629edf7136e166938075641 100644
60--- a/tests/test_maybeworkon.zunit
61+++ b/tests/test_maybeworkon.zunit
62@@ -23,6 +23,18 @@
63 rm -rf "$TARGET"
64 }
65
66+@test '_maybeworkon - do not activate paths which are potentially inscure' {
67+ VIRTUAL_ENV=""
68+
69+ run _maybeworkon "$TARGET/../../../" virtualenv
70+
71+ assert $state equals 0
72+
73+ # first line would be the "switching virtualenv: ...."
74+ assert "${lines[2]}" same_as "AUTOSWITCH WARNING: target virtualenv contains invalid characters"
75+ assert "${lines[3]}" same_as "virtualenv activation cancelled"
76+}
77+
78 @test '_maybeworkon - error message if virtualenv can not be found' {
79 VIRTUAL_ENV=""
80