Deployment branch text is reinterpreted as Git command arguments
Fixed in: main and 4.0.0-canary-6848; stable 3.10.2 still uses the old command path
details
- Finding IDs
- F-DOCUSAURUS-DEPLOY-ARGINJECT-001
- Status
- merged to main/pre-release only
- Fixed in
- main and 4.0.0-canary-6848; stable 3.10.2 still uses the old command path
- Note
- The reported path requires control of the deployment branch supplied to the deploy command. Whitespace in that value could introduce additional Git arguments when the command string was parsed. The 3 September 2026 execa migration replaces commandSync strings with executable-and-argument arrays, keeping the branch value as one argument for clone, checkout and push. The change is present in the published 4.0.0-canary-6848 package; the inspected stable 3.10.2 source still uses commandSync. This records closure of the argument-splitting path, not proof that every possible Git option or deployment configuration is safe. No stable fixed release is claimed. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-DOCUSAURUS-DEPLOY-ARGINJECT-001: Code / markup injection. Branch-name data is interpolated into a command string instead of remaining one argument. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-DOCUSAURUS-DEPLOY-ARGINJECT-001
Security area (1seal assessment): Semantics. Branch-name data is interpolated into a command string instead of remaining one argument. Reviewed 26 Sep 2026.