Sitelet https://github.com/flutter/flutter/pull/192434
Skip to content

[flutter_tools] validate placeholder type in gen-l10n - #192434

Merged
auto-submit[bot] merged 3 commits into
flutter:masterfrom
bkonyi:issue-192130
Sep 10, 2026
Merged

auto-submit[bot] merged 3 commits into
flutter:masterfrom
bkonyi:issue-192130

Conversation

@bkonyi

@bkonyi bkonyi commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Description

Fixes #192130

In flutter gen-l10n, placeholder types specified in .arb files were previously parsed with _stringAttribute without validating whether the string is a valid Dart type identifier. When generating method parameter signatures in generateMethodParameters, ${placeholder.type} ${placeholder.name} was directly interpolated, allowing crafted type strings to prematurely terminate the method declaration and inject arbitrary code.

This change:

  1. Validates placeholder types during Placeholder parsing in gen_l10n_types.dart using _isValidType, ensuring only valid Dart type names (including generic type parameters, library prefixes, and nullable types) are accepted.
  2. Throws an L10nException if an invalid type string is encountered.
  3. Adds regression test in generate_localizations_test.dart.

Related Issues

Fixes #192130

Tests

  • Added regression test in packages/flutter_tools/test/general.shard/generate_localizations_test.dart.

Validates placeholder type in gen-l10n ARB files to ensure that only valid Dart type names are accepted, preventing arbitrary code injection into generated localizations code.

Fixes flutter#192130
@flutter-dashboard flutter-dashboard Bot added the CICD Run CI/CD label Sep 8, 2026
@github-actions github-actions Bot added the tool Affects the "flutter" command-line tool. See also t: labels. label Sep 8, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces validation for placeholder types in Flutter localization files to ensure they are valid Dart type names, throwing an L10nException if validation fails, and adds a corresponding regression test. Feedback on the changes identifies a potential code injection vulnerability in the regular expression used for validation due to a greedy wildcard inside the generic type parameters pattern, and suggests a stricter pattern to resolve this issue.

Comment thread packages/flutter_tools/lib/src/localizations/gen_l10n_types.dart
@bkonyi
bkonyi requested a review from dcharkes September 9, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CICD Run CI/CD tool Affects the "flutter" command-line tool. See also t: labels.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

flutter gen-l10n does not validate placeholder type, allowing code injection into generated Dart from .arb files

2 participants