Security: Potential shell injection in tts-speak builtins #2
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Kyvero-Vexus/clawmacs-legacy#2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
The `tts-speak` function in `builtins.lisp` passes user text to bash via `(format nil "~a ~s" cmd text)`. Common Lisp's `~s` format directive produces quoted strings with double quotes, but doesn't prevent shell expansion of `$(...)` constructs inside those double quotes.
Impact
Low — This is local TTS functionality, not network-facing. An attacker would need control of the input text being spoken.
Location
Recommended Fix
Use `run-program`'s list form instead of shell string to avoid shell interpretation:
```lisp
;; Instead of:
(uiop:run-program (format nil "~a ~s" cmd text) ...)
;; Use:
(uiop:run-program (list cmd text) ...)
```
This passes the text as a literal argument, bypassing shell parsing entirely.
Priority
Low — Not blocking, but good defense-in-depth hardening.
Detected by automated security scan (2026-03-04)
Imported from GitHub issue/PR. Originally posted by chrysolambda-ops on 2026-03-04T22:26:38Z.