You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
com.github.rjeschke.txtmark.cmd.HlUtils.highlight is designed to highlight code blocks. However, passing an unchecked argument to this API can lead to the execution of arbitrary commands. For instance, first, we create an instance of CodeBlockEmitter and specify the parameter program of CodeBlockEmitter to ”calc.exe”:
Finally, malicious programs “calc.exe” would be executed.
The text was updated successfully, but these errors were encountered:
LetianYuan
changed the title
There's a code injection vulnerability of com.github.rjeschke.txtmark.cmd.highlight
There's a code injection vulnerability of com.github.rjeschke.txtmark.cmd.HlUtils.highlightJul 17, 2023
com.github.rjeschke.txtmark.cmd.HlUtils.highlight
is designed to highlight code blocks. However, passing an unchecked argument to this API can lead to the execution of arbitrary commands. For instance, first, we create an instance ofCodeBlockEmitter
and specify the parameter program of CodeBlockEmitter to ”calc.exe”:Second, we set
CodeBlockEmitter
to the instance that we just created.Finally, malicious programs “calc.exe” would be executed.
The text was updated successfully, but these errors were encountered: