Amber compiles {expr} interpolations inside $ ... $ command blocks to unquoted bash expansions, e.g. wget -qO ${local_filename} ${url} in the generated install.sh files. The version option is free-form text from a user's devcontainer.json, so a value containing spaces or glob characters word-splits into extra command arguments and fails in confusing ways (and is generally not a great injection surface).
Two complementary fixes:
- Quote interpolated values inside the Amber command blocks where they are used as single arguments, e.g.
$ wget -qO "{local_filename}" "{url}" $, across lib/ and the feature scripts.
- Validate the
version option early against a conservative pattern (e.g. ^[A-Za-z0-9._-]+$) and fail with a clear error message otherwise.
Touches lib/download.ab among others, so this should be coordinated with (or rebased on) PR #33, which rewrites the latest-version lookup in that file.
Amber compiles
{expr}interpolations inside$ ... $command blocks to unquoted bash expansions, e.g.wget -qO ${local_filename} ${url}in the generatedinstall.shfiles. Theversionoption is free-form text from a user'sdevcontainer.json, so a value containing spaces or glob characters word-splits into extra command arguments and fails in confusing ways (and is generally not a great injection surface).Two complementary fixes:
$ wget -qO "{local_filename}" "{url}" $, acrosslib/and the feature scripts.versionoption early against a conservative pattern (e.g.^[A-Za-z0-9._-]+$) and fail with a clear error message otherwise.Touches
lib/download.abamong others, so this should be coordinated with (or rebased on) PR #33, which rewrites the latest-version lookup in that file.