Skip to content

Harden CLI external-tool execution paths against command injection - #50510

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/sighthound-security-findings
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/sighthound-security-findings

Conversation

Copilot AI commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Sighthound identified critical command-injection risks in several pkg/cli paths where external tool commands were assembled from dynamic input. This change hardens those call sites by eliminating shell-style command construction and enforcing explicit argv-based execution.

  • Security hardening in CLI exec call sites

    • Reworked vulnerable paths in:
      • pkg/cli/runner_guard.go
      • pkg/cli/grant.go
      • pkg/cli/poutine.go
      • pkg/cli/upgrade_command.go
    • Removed shell-interpolated command building patterns and switched to direct executable + argument-slice invocation.
  • Argument handling constraints

    • Preserved existing behavior while tightening construction of command arguments.
    • Ensured dynamic values are passed as discrete argv entries instead of being embedded into command strings.
  • Regression coverage

    • Added/updated focused tests around affected execution paths to assert safe command formation and guard against regressions in command invocation behavior.
// Before (unsafe pattern)
cmd := exec.Command("sh", "-c", fmt.Sprintf("tool --flag %s", userValue))

// After (safe pattern)
cmd := exec.Command("tool", "--flag", userValue)

Copilot AI linked an issue Aug 5, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Fix security findings in GitHub/gh-aw Harden CLI external-tool execution paths against command injection Aug 5, 2026
Copilot AI requested a review from pelikhan August 5, 2026 07:16
@pelikhan pelikhan closed this Aug 5, 2026
@github-actions
github-actions Bot deleted the copilot/sighthound-security-findings branch September 6, 2026 02:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[sighthound] Security findings in github/gh-aw

2 participants