Skip to content

[Aikido] Prevent command injection in replace_version Makefile target - #740

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137917819-e8ge
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137917819-e8ge

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a command injection vulnerability in the replace_version Makefile target by implementing strict semantic versioning validation before executing shell commands. The fix adds a regex pattern check to ensure the version parameter matches the expected format (e.g., 1.2.3, 1.2.3-alpha.1) and rejects any malformed input that could be exploited for command injection. The Makefile has been updated to validate user input and provide clear error messages when invalid version formats are supplied.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811708331
HIGH
The publish workflows derive a version from GITHUB_REF and pass it to make replace_version as a command-line Make variable. Make later expands that value directly into the poetry version $(version) recipe. A tag such as dev-v1.0.0;command therefore produces a recipe equivalent to poetry version 1.0.0;command, and the shell executes the injected command. Git ref syntax permits semicolons, while the workflow's tag filters do not enforce a package-version grammar. The same issue exists in the production release workflow. Code executed in this job can alter checked-out source or build inputs before artifacts are constructed and published, enabling a repository writer with matching-tag permissions to publish attacker-controlled package contents through the configured package-publishing path.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant