Security vulnerabilities and automated fixes for security hardening issues
2 posts found
A high-severity command injection vulnerability was discovered in `events/console/line.js` where user-controlled input was passed directly to `child_process.exec()`. The fix replaces the dangerous `exec()` function with the safer `execFile()` API, implements a strict whitelist of allowed commands, and adds comprehensive argument validation to prevent remote code execution.
A pnpm workspace configuration was missing the `minimumReleaseAge` setting, creating a supply chain vulnerability where newly published (and potentially malicious) packages could be installed immediately. By adding a 10,080-minute (7-day) minimum release age to `pnpm-workspace.yaml`, the project now enforces a critical delay that allows the security community time to identify and report malicious or unstable packages before they reach production environments.