Repository navigation
fix(core): validate git args in Windows sandbox to block silent git diff --output - #29184
PakCyberbot wants to merge 1 commit into
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request strengthens the security of the Windows sandbox by aligning its git command validation logic with the existing POSIX implementation. By centralizing the logic for identifying read-only and dangerous git commands, the system now correctly blocks or flags potentially malicious git operations that were previously treated as safe. This change effectively mitigates a reported security vulnerability related to arbitrary file overwrites via git flag injection. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
📊 PR Size: size/M
|
There was a problem hiding this comment.
Code Review
This pull request refactors the git command safety validation logic by extracting it into reusable helper functions (isGitCommandReadOnly and isGitCommandDangerous) and integrating them into the Windows command safety checks, along with adding comprehensive unit tests. However, the review feedback identifies critical security vulnerabilities in both helper functions. Specifically, they fail to validate and block dangerous git global options such as --exec-path, --git-dir, -C, and --work-tree, which could allow an attacker to bypass the sandbox and execute arbitrary commands.
|
proper-validated-except-diffoutput.mp4 |
There was a problem hiding this comment.
Code Review
This pull request refactors the git command safety checks by extracting the validation logic into shared utility functions (isGitCommandReadOnly and isGitCommandDangerous) and integrating them into the Windows sandbox implementation to ensure cross-platform consistency. The review feedback highlights critical security vulnerabilities where dangerous global git options, such as --exec-path and --git-dir, are not blocked or flagged, potentially leading to Remote Code Execution (RCE) and sandbox escape. Additionally, the reviewer recommends expanding the test suite to cover short-form options like -o to prevent regressions.
|
Hi there! Thank you for your interest in contributing to Gemini CLI. To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'. This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
|
This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding. |
Summary
On Windows, any
git status | log | diff | show | branchis treated as read-only and runs without a confirmation prompt, regardless of its arguments. Sogit diff --output=<path>runs silently in the default (non-YOLO) mode.That flag opens the target file and truncates it before writing any diff — an arbitrary file overwrite with no prompt (overwrite a config, profile, or any important file).
POSIX already validates these args. The Windows branch only checks the sub-command name and skips the flags — it even says so:
Fixes #29189
Fix
Reuse the POSIX validation instead of a second, weaker check:
isGitCommandReadOnly/isGitCommandDangerousas shared helpers insandbox/utils/commandSafety.ts(pure refactor, POSIX behavior unchanged).isKnownSafeCommand/isDangerousCommandnow delegate to them.Now
--output(both forms),--ext-diff,--textconv,--exec,-cconfig overrides, andgit branch -Dall require confirmation. Plaingit diff/status/logstay silent as before.Testing
tsc --noEmitclean.PolicyEngineon Windows: write-capable git →ASK_USER, read-only git →ALLOW.Related report
Reported to the Google AI VRP:
https://issuetracker.google.com/issues/550750284 - Security Control Bypass in Gemini CLI via git diff --output Flag Injection Leading to Unprompted Arbitrary File Overwrite
I used AI assistance on this, but didn't submit it blindly — I read through the sandbox/policy code, confirmed the root cause, built and reproduced both the vulnerable and fixed behavior locally, and reviewed the diff. Please still verify on your end. Thanks.