Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@lociko
Copy link
Contributor

@lociko lociko commented Sep 29, 2025

Issue #, if available:

Description of changes:

Amazon Q CLI does not properly validates the usage of the find command. While the code attempts to block dangerous options like -exec, -ok, -delete, and -fprint, it overlooks -fls, which can write arbitrary file listings to attacker-controlled paths. This can lead to arbitrary file creation or overwrite in sensitive directories.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lociko
Copy link
Contributor Author

lociko commented Oct 3, 2025

Any updates?

@kkashilk kkashilk merged commit 027c3c0 into aws:main Oct 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants