T09 · Insecure Skill Coding Practices
- Location
api/browser/open-url.js:29- Finding
Shell Command Injection in URL Opener
- Content
View full analysis
- Remediation
View remediation
{ const child = spawn(executable, args, { shell: false, stdio: 'ignore' }) child.once('error', reject) child.once('exit', code => { if (code === 0) resolve() else reject(new Error(`Browser opener exited with code ${code}`)) }) }) } async function openUrl(url) { if (!url) throw new Error('URL is required') if (!isAllowedUrl(url)) throw new Error('URL not allowed') if (process.platform === 'darwin') { await run('open', [url]) } else if (process.platform === 'win32') { await run('cmd.exe', ['/d', '/s', '/c', 'start', '', url]) } else { await run('xdg-open', [url]) } } ``` On Windows, avoid `cmd.exe` where possible because it introduces another command parser. Prefer a shell-free platform API or a well-reviewed browser-opening library. ]]>
