Skip to content

Fix local command execution issue closes #494#497

Open
joernchen wants to merge 2 commits intofelixfbecker:masterfrom
joernchen:patch-1
Open

Fix local command execution issue closes #494#497
joernchen wants to merge 2 commits intofelixfbecker:masterfrom
joernchen:patch-1

Conversation

@joernchen
Copy link
Copy Markdown

This PR will fix a command execution issue in the extension.

execa version 1.0 used in this extension searches the local path first when trying to find the php executable. By this a crafted project can override the php binary and execute arbitrary code.

@joernchen
Copy link
Copy Markdown
Author

@felixfbecker is there anything more I could do to help getting this merged and the command execution issue resolved?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant