From cdf86e95884f2b1ad90ebe105d10aea68a7804b4 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Wed, 7 Oct 2026 13:33:50 +0000 Subject: [PATCH] Fix command injection vulnerability in PowerShell notification Replaced the vulnerable `-Command` invocation that relied on environment variables with a dynamically generated, base64-encoded PowerShell script passed via `-EncodedCommand`. The user-supplied title and body are also base64-encoded and decoded at runtime within the PowerShell script, eliminating any possibility of command injection. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- stdlib/src/notification.rs | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/stdlib/src/notification.rs b/stdlib/src/notification.rs index 8db24c7a..b4898fe7 100644 --- a/stdlib/src/notification.rs +++ b/stdlib/src/notification.rs @@ -32,14 +32,20 @@ impl StdlibRegistry { let body = args[1].to_string(); #[cfg(target_os = "windows")] { + use base64::Engine; use std::process::Command; + + let b64_title = base64::engine::general_purpose::STANDARD.encode(title.encode_utf16().flat_map(|c| c.to_le_bytes()).collect::>()); + let b64_body = base64::engine::general_purpose::STANDARD.encode(body.encode_utf16().flat_map(|c| c.to_le_bytes()).collect::>()); + + let script = format!( + "Add-Type -AssemblyName PresentationFramework; [System.Windows.MessageBox]::Show([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('{}')), [System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('{}')))", + b64_body, b64_title + ); + let b64_script = base64::engine::general_purpose::STANDARD.encode(script.encode_utf16().flat_map(|c| c.to_le_bytes()).collect::>()); + let _ = Command::new("powershell") - .env("TS_NOTIFY_TITLE", &title) - .env("TS_NOTIFY_BODY", &body) - .args([ - "-Command", - "[System.Windows.MessageBox]::Show($env:TS_NOTIFY_BODY, $env:TS_NOTIFY_TITLE)" - ]) + .args(["-EncodedCommand", &b64_script]) .spawn(); } #[cfg(not(target_os = "windows"))]