Skip to content

Potential for shell injection #2

@thclark

Description

@thclark

Malicious repositories could configure their pre-commit for shell injection here.

Use either validation of paths or (preferably) avoid os.system altogether and call sphinx directly.

When complete, report back in at pre-commit/pre-commit.com#362

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions