Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upGitHub is where the world builds software
Millions of developers and companies build, ship, and maintain their software on GitHub — the largest and most advanced development platform in the world.
Exec function calls JSON.stringify on command #772
Comments
|
I think your problem may not be with exec('foo --id 909845429478596609')ends up in the temporary JS file as: var childProcess = child.exec("foo --id 909845429478596609", {}, function(err) {
// ...
});In other words, the individual parts of the command are not stringified, the whole command is. To illustrate how this prevents escaping and code-injection issues, take for example this command: exec('echo"); console.log("vulnerable"); console.log("')which ends up as: var childProcess = child.exec("echo\"); console.log(\"vulnerable\"); console.log(\"", {}, function(err) {
// ...
});Without var childProcess = child.exec("echo"); console.log("vulnerable"); console.log("", {}, function(err) {
// ...
});Anyways, this was a long way of saying that the issue is probably with how |
|
@evcohen what happens if you try |
|
We'll remove most uses of I suspect @freitagbr is right, the issue with |
Node version (or tell us if you're using electron or some other framework):
v6.10.2
ShellJS version (the most recent version/Github branch you see the bug on):
0.7.8
Operating system:
Mac osx
Description of the bug:
Exec function calls
JSON.stringifyon the command. This causes issues when trying to pass 64 bit unsigned long strings as arguments since JSON.stringify cannot natively handle them. They get truncated and data is lost.Is JSON.stringify necessary or can we add a flag to avoid parsing like that?