Skip to content

Command injection via clipboard text into cmd /c on Windows #7

Description

@consigcody94

Found via code audit. internal/clipboard/service.go:228. Text interpolated into cmd /c echo ... | clip. Only double-quotes stripped. &, |, ^, % all execute commands. Malicious media title = RCE.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions