Security: Potential shell injection in tts-speak builtins #2

Open
opened 2026-03-04 22:26:38 +00:00 by chrysolambda-ops · 0 comments
chrysolambda-ops commented 2026-03-04 22:26:38 +00:00 (Migrated from github.com)

Description

The `tts-speak` function in `builtins.lisp` passes user text to bash via `(format nil "~a ~s" cmd text)`. Common Lisp's `~s` format directive produces quoted strings with double quotes, but doesn't prevent shell expansion of `$(...)` constructs inside those double quotes.

Impact

Low — This is local TTS functionality, not network-facing. An attacker would need control of the input text being spoken.

Location

  • File: `builtins.lisp`
  • Function: `tts-speak`

Use `run-program`'s list form instead of shell string to avoid shell interpretation:

```lisp
;; Instead of:
(uiop:run-program (format nil "~a ~s" cmd text) ...)

;; Use:
(uiop:run-program (list cmd text) ...)
```

This passes the text as a literal argument, bypassing shell parsing entirely.

Priority

Low — Not blocking, but good defense-in-depth hardening.


Detected by automated security scan (2026-03-04)


Imported from GitHub issue/PR. Originally posted by chrysolambda-ops on 2026-03-04T22:26:38Z.

## Description The \`tts-speak\` function in \`builtins.lisp\` passes user text to bash via \`(format nil \"~a ~s\" cmd text)\`. Common Lisp's \`~s\` format directive produces quoted strings with double quotes, but doesn't prevent shell expansion of \`$(...)\` constructs inside those double quotes. ## Impact **Low** — This is local TTS functionality, not network-facing. An attacker would need control of the input text being spoken. ## Location - File: \`builtins.lisp\` - Function: \`tts-speak\` ## Recommended Fix Use \`run-program\`'s list form instead of shell string to avoid shell interpretation: \`\`\`lisp ;; Instead of: (uiop:run-program (format nil \"~a ~s\" cmd text) ...) ;; Use: (uiop:run-program (list cmd text) ...) \`\`\` This passes the text as a literal argument, bypassing shell parsing entirely. ## Priority Low — Not blocking, but good defense-in-depth hardening. --- *Detected by automated security scan (2026-03-04)* --- Imported from [GitHub issue/PR](https://github.com/Kyvero-Vexus/clawmacs-legacy/issues/2). Originally posted by [chrysolambda-ops](https://github.com/chrysolambda-ops) on 2026-03-04T22:26:38Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Kyvero-Vexus/clawmacs-legacy#2
No description provided.