Skip to content
This repository was archived by the owner on Sep 28, 2026. It is now read-only.

Fix PowerShell command injection in preview command - #567

Closed
viperdan13 wants to merge 1 commit into
microsoft:mainfrom
viperdan13:fix/powershell-command-injection
Closed

viperdan13 wants to merge 1 commit into
microsoft:mainfrom
viperdan13:fix/powershell-command-injection

Conversation

@viperdan13

Copy link
Copy Markdown

PR Summary

Basically, the preview command was putting file paths straight into a PowerShell command. A path containing characters like ;, &, backticks, or a newline could run extra commands.

This changes the preview to use execFile with shell: false. The PowerShell command is fixed, and the paths are passed as plain environment values, so PowerShell treats them as data instead of commands.

It also adds regression tests for normal and malicious-looking paths and updates the changelog.

PR Checklist

  • PR has a meaningful title
  • Summarized changes
  • Change is not breaking
  • This PR is ready to merge and is not Work in Progress
  • Code changes
    • Link to a filed issue
    • Change log has been updated with change under unreleased section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

There are a couple of small but concrete correctness/maintainability issues in the new invocation helper and changelog formatting that should be addressed before merging.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR mitigates PowerShell command injection risk in the PSDocs preview command by switching to an execFile-based invocation that keeps user-controlled paths out of the PowerShell command text and instead passes them via environment variables.

Changes:

  • Replaces exec + interpolated PowerShell string with execFile + shell: false and a centralized invocation builder.
  • Adds regression tests to ensure paths (including malicious-looking fragments) never appear in the PowerShell command text.
  • Updates the changelog to note the security fix.
File summaries
File Description
src/extension.ts Uses execFile and delegates PowerShell invocation construction to a helper to avoid command injection.
src/psdocsInvocation.ts Introduces a single function to build the safe pwsh -Command ... invocation with env-passed paths.
src/test/suite/psdocsInvocation.test.ts Adds tests asserting paths never appear in the PowerShell command/args and are only passed via env.
CHANGELOG.md Documents the security fix in the Unreleased section.
Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/psdocsInvocation.ts
Comment on lines +6 to +8
const PSDOCS_COMMAND =
"Import-Module PSDocs.Azure; Invoke-PSDocument -Module PSDocs.Azure -InputObject $env:PSDOCS_VSCODE_TEMPLATE_PATH -OutputPath $env:PSDOCS_VSCODE_OUTPUT_PATH;";

Comment thread CHANGELOG.md
Comment on lines 9 to 11
## Unreleased
- Fixed PowerShell command injection in the PSDocs preview command.
Updated Pipeline step to remove GitHub release.
@vicperdana

Copy link
Copy Markdown
Contributor

Replaced by #568, opened from the vicperdana account.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants