fix(security): broaden git_gate subprocess bypass detection — word-boundary matching catches os.system string-style, bare popen, and escaped-quote patterns (Issue #561)

This commit is contained in:
AIOSAI
2026-05-16 11:48:37 -07:00
parent d7dbb6291b
commit a22a1b174b
+3 -3
View File
@@ -148,9 +148,9 @@ def main():
return
# Subprocess bypass detection — scan raw command for git/gh inside
# subprocess.run/call/Popen/os.system patterns before stripping quotes.
if re.search(r"subprocess\.\w+|os\.system|os\.popen|Popen", cmd):
if re.search(r"['\"]git['\"]|['\"]gh['\"]", cmd):
# subprocess/os execution patterns before stripping quotes.
if re.search(r"subprocess\.\w+|os\.system|os\.popen|Popen|(?<!\w)popen\s*\(|(?<!\w)system\s*\(", cmd):
if re.search(r"\bgit\b|\bgh\b", cmd):
_block(GIT_REDIRECT)
# Strip quoted strings before matching — text inside "..." or '...' is data