Skip to content

Security issue with bash-git-prompt ? #310

@chmike

Description

@chmike

I have seen this report of possible hack with some shell git prompts. I didn't test if it works with bash-git-prompt.

The trick is to name a git branch as '$(./nastyScript)'. When the shell displays the branch name, the shell will execute nastyScript which should be in the local directory.

Is bash-git-prompt exposed to this risk ?

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions