Skip to content

Conversation

@netomi
Copy link
Collaborator

@netomi netomi commented Dec 20, 2025

This PR ensures that tag names are properly escaped and quoted before using it as parameter for a shell command.

Malicious actors could forge a tag name for a shell injection attack thus we need to be very careful when passing a user controlled argument like the tag to a shell.

@netomi netomi requested a review from kineticsquid December 20, 2025 20:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant