Skip to content

Commit c483e9a

Browse files
Copilotpontemonti
andauthored
Fix shell injection vulnerability in /resolve-review command (#165)
* Initial plan * Add shell injection protection for branch names in resolve-review command Co-authored-by: pontemonti <7850950+pontemonti@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: pontemonti <7850950+pontemonti@users.noreply.github.com>
1 parent 76ceea4 commit c483e9a

1 file changed

Lines changed: 17 additions & 2 deletions

File tree

‎.claude/commands/resolve-review.md‎

Lines changed: 17 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -157,12 +157,27 @@ For each issue marked "Agent Resolvable: Yes":
157157
1. Push the fix branch to origin:
158158
```bash
159159
cd .worktrees/pr-<PR_NUMBER>-fixes
160-
git push -u origin <FIX_BRANCH_NAME>
160+
git push -u origin "$FIX_BRANCH_NAME"
161161
```
162162
163163
2. Create a PR to merge fixes into the original PR branch:
164164
```bash
165-
gh pr create --base <ORIGINAL_PR_HEAD_BRANCH> --head <FIX_BRANCH_NAME> --title "fix: address code review comments for PR #<PR_NUMBER>" --body "$(cat <<'EOF'
165+
# Validate that branch names are safe (alphanumerics, dot, slash, dash, underscore)
166+
case "$ORIGINAL_PR_HEAD_BRANCH" in
167+
(*[!A-Za-z0-9._/-]*|'')
168+
echo "Error: ORIGINAL_PR_HEAD_BRANCH contains unsafe characters: $ORIGINAL_PR_HEAD_BRANCH" >&2
169+
exit 1
170+
;;
171+
esac
172+
173+
case "$FIX_BRANCH_NAME" in
174+
(*[!A-Za-z0-9._/-]*|'')
175+
echo "Error: FIX_BRANCH_NAME contains unsafe characters: $FIX_BRANCH_NAME" >&2
176+
exit 1
177+
;;
178+
esac
179+
180+
gh pr create --base "$ORIGINAL_PR_HEAD_BRANCH" --head "$FIX_BRANCH_NAME" --title "fix: address code review comments for PR #<PR_NUMBER>" --body "$(cat <<'EOF'
166181
## Summary
167182
Addresses agent-resolvable code review comments from PR #<PR_NUMBER>.
168183

0 commit comments

Comments
 (0)