From b5e0199a9b6016d29345b89381b47f8851db86d7 Mon Sep 17 00:00:00 2001 From: RHEL Packaging Agent Date: Wed, 29 Jul 2026 12:40:15 +0000 Subject: [PATCH] patch 9.2.0736: potential command execution in PHP omni-completion Problem: With PHP omni-completion, a crafted file can potentially execute arbitrary commands when completing a class member. Solution: Quote the class name before inserting it into the search() pattern run via win_execute(). --- runtime/autoload/phpcomplete.vim | 3 ++- src/testdir/Make_all.mak | 2 ++ src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++ 3 files changed, 39 insertions(+), 1 deletion(-) create mode 100644 src/testdir/test_plugin_phpcomplete.vim diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim index 4041a80..38dc1b0 100644 --- a/runtime/autoload/phpcomplete.vim +++ b/runtime/autoload/phpcomplete.vim @@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam let result = [] let popup_id = popup_create(a:file_lines, {'hidden': v:true}) - call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')') + call win_execute(popup_id, 'call search(' + \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')') call win_execute(popup_id, "let cfline = line('.')") call win_execute(popup_id, "call search('{')") call win_execute(popup_id, "let endline = line('.')") diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak index 2430bc7..c5d6e01 100644 --- a/src/testdir/Make_all.mak +++ b/src/testdir/Make_all.mak @@ -211,6 +211,7 @@ NEW_TESTS = \ test_perl \ test_plugin_ccomplete \ test_plugin_tar \ + test_plugin_phpcomplete \ test_plus_arg_edit \ test_popup \ test_popupwin \ @@ -451,6 +452,7 @@ NEW_TESTS_RES = \ test_perl.res \ test_plugin_ccomplete.res \ test_plugin_tar.res \ + test_plugin_phpcomplete.res \ test_plus_arg_edit.res \ test_popup.res \ test_popupwin.res \ diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim new file mode 100644 index 0000000..7f66be4 --- /dev/null +++ b/src/testdir/test_plugin_phpcomplete.vim @@ -0,0 +1,35 @@ +" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim). + +" A buffer class name is interpolated into a search() pattern run via +" win_execute(). Without escaping, "'" closes the string and "|" starts a new +" Ex command, so the name runs as an Ex command during completion. +func Test_phpcomplete_no_exec_via_class_name() + unlet! g:phpcomplete_injected + let lines = [' 0, 'no class structure returned') + call assert_match('class Foo', result[0].content, + \ 'class body missing from returned content') + call assert_match('bar', result[0].content, + \ 'class member missing from returned content') +endfunc + +" vim: shiftwidth=2 sts=2 expandtab