From d7dbb6291b1544954f6ba10e4487f04511e59d86 Mon Sep 17 00:00:00 2001 From: AIOSAI Date: Sat, 16 May 2026 10:38:20 -0700 Subject: [PATCH] =?UTF-8?q?fix(security):=20block=20Python=20subprocess=20?= =?UTF-8?q?git=20bypass=20in=20git=5Fgate.py=20=E2=80=94=20detects=20subpr?= =?UTF-8?q?ocess.run/call/Popen/os.system=20wrapping=20git/gh=20commands?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/hooks/git_gate.py | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.claude/hooks/git_gate.py b/.claude/hooks/git_gate.py index 77d5df46..afdb2bb8 100755 --- a/.claude/hooks/git_gate.py +++ b/.claude/hooks/git_gate.py @@ -146,10 +146,17 @@ def main(): cmd = tool_input.get("command", "") if not cmd: return + + # Subprocess bypass detection — scan raw command for git/gh inside + # subprocess.run/call/Popen/os.system patterns before stripping quotes. + if re.search(r"subprocess\.\w+|os\.system|os\.popen|Popen", cmd): + if re.search(r"['\"]git['\"]|['\"]gh['\"]", cmd): + _block(GIT_REDIRECT) + # Strip quoted strings before matching — text inside "..." or '...' is data # (PR descriptions, commit messages, examples in docs), not code to enforce. scan = re.sub(r'"(?:[^"\\]|\\.)*"', '""', cmd) - scan = re.sub(r"'(?:[^'\\]|\\.)*'", "''", scan) + scan = re.sub(r"'(?:[^'\\]|\\.)*'", "''", cmd) if ( BLOCKED_GIT_RE.search(scan) or BLOCKED_GIT_STASH_RE.search(scan)