This repository was archived by the owner on Sep 28, 2026. It is now read-only.
Fix PowerShell command injection in preview command - #567
Closed
viperdan13 wants to merge 1 commit into
Closed
viperdan13 wants to merge 1 commit into
viperdan13 wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Vic Perdana (vicperdana)
September 9, 2026 12:30
View session
There was a problem hiding this comment.
🟡 Changes recommended
There are a couple of small but concrete correctness/maintainability issues in the new invocation helper and changelog formatting that should be addressed before merging.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR mitigates PowerShell command injection risk in the PSDocs preview command by switching to an execFile-based invocation that keeps user-controlled paths out of the PowerShell command text and instead passes them via environment variables.
Changes:
- Replaces
exec+ interpolated PowerShell string withexecFile+shell: falseand a centralized invocation builder. - Adds regression tests to ensure paths (including malicious-looking fragments) never appear in the PowerShell command text.
- Updates the changelog to note the security fix.
File summaries
| File | Description |
|---|---|
| src/extension.ts | Uses execFile and delegates PowerShell invocation construction to a helper to avoid command injection. |
| src/psdocsInvocation.ts | Introduces a single function to build the safe pwsh -Command ... invocation with env-passed paths. |
| src/test/suite/psdocsInvocation.test.ts | Adds tests asserting paths never appear in the PowerShell command/args and are only passed via env. |
| CHANGELOG.md | Documents the security fix in the Unreleased section. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+6
to
+8
| const PSDOCS_COMMAND = | ||
| "Import-Module PSDocs.Azure; Invoke-PSDocument -Module PSDocs.Azure -InputObject $env:PSDOCS_VSCODE_TEMPLATE_PATH -OutputPath $env:PSDOCS_VSCODE_OUTPUT_PATH;"; | ||
|
|
Comment on lines
9
to
11
| ## Unreleased | ||
| - Fixed PowerShell command injection in the PSDocs preview command. | ||
| Updated Pipeline step to remove GitHub release. |
Contributor
|
Replaced by #568, opened from the vicperdana account. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Summary
Basically, the preview command was putting file paths straight into a PowerShell command. A path containing characters like
;,&, backticks, or a newline could run extra commands.This changes the preview to use
execFilewithshell: false. The PowerShell command is fixed, and the paths are passed as plain environment values, so PowerShell treats them as data instead of commands.It also adds regression tests for normal and malicious-looking paths and updates the changelog.
PR Checklist