require arguments to be shell interpreted to be flagged by indirect-command-injection

This commit is contained in:
erik-krogh
2023-05-17 11:05:29 +02:00
parent b46983a381
commit 3293a55e8f
2 changed files with 8 additions and 2 deletions

View File

@@ -144,4 +144,6 @@ cp.exec("cmd.sh " + require("optimist").argv.foo); // NOT OK
cp.exec("cmd.sh " + program.opts().pizzaType); // NOT OK
cp.exec("cmd.sh " + program.pizzaType); // NOT OK
cp.execFile(program.opts().pizzaType, ["foo", "bar"]); // OK
});