Skip to content

KC-1471: Prevent newline injection in connect command prompts - #2403

Merged
sk-keeper merged 1 commit into
releasefrom
KC-1471
Sep 30, 2026
Merged

sk-keeper merged 1 commit into
releasefrom
KC-1471

Conversation

@sshrushanth-ks

Copy link
Copy Markdown
Contributor

Summary

Escape control characters instead of deleting them, and properly handle shell comments to expose multi-statement payloads in the confirmation prompt. Attackers with Can Edit on shared records could inject commands that execute silently, exfiltrating device credentials without operator visibility.

Changes

  • keepercommander/commands/connect_prompts.py:
    • Escape control chars as visible sequences (\n, \t, \xHH) instead of deleting
    • Handle shell comments (#) to prevent comment-based newline injection
  • unit-tests/test_connect_security.py:
    • Add tests for newline injection, comment handling, and control character escaping
    • Verify statement breakdown exposes multi-statement payloads

* Fix: Prevent newline injection in connect command prompts
Escape control chars and handle comments to prevent hidden commands from
bypassing the confirmation prompt. Attackers with Can Edit on shared records
could exfiltrate device credentials without operator visibility.

* Add word-boundary check for shell comments; cover with 3 regression tests
@sshrushanth-ks
sshrushanth-ks marked this pull request as ready for review September 30, 2026 12:24
@sshrushanth-ks sshrushanth-ks self-assigned this Sep 30, 2026
@sk-keeper
sk-keeper merged commit ab573d4 into release Sep 30, 2026
4 checks passed
@sk-keeper
sk-keeper deleted the KC-1471 branch September 30, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants