Skip to content

fix(core): validate git args in Windows sandbox to block silent git diff --output - #29184

Closed
PakCyberbot wants to merge 1 commit into
google-gemini:mainfrom
PakCyberbot:main
Closed

PakCyberbot wants to merge 1 commit into
google-gemini:mainfrom
PakCyberbot:main

Conversation

@PakCyberbot

@PakCyberbot PakCyberbot commented Sep 3, 2026 •

Copy link
Copy Markdown

Summary

On Windows, any git status | log | diff | show | branch is treated as read-only and runs without a confirmation prompt, regardless of its arguments. So git diff --output=<path> runs silently in the default (non-YOLO) mode.

That flag opens the target file and truncates it before writing any diff — an arbitrary file overwrite with no prompt (overwrite a config, profile, or any important file).

POSIX already validates these args. The Windows branch only checks the sub-command name and skips the flags — it even says so:

// In a full implementation, we'd port the sub-command validation too.

Fixes #29189

Fix

Reuse the POSIX validation instead of a second, weaker check:

  • Extract isGitCommandReadOnly / isGitCommandDangerous as shared helpers in sandbox/utils/commandSafety.ts (pure refactor, POSIX behavior unchanged).
  • Windows isKnownSafeCommand / isDangerousCommand now delegate to them.

Now --output (both forms), --ext-diff, --textconv, --exec, -c config overrides, and git branch -D all require confirmation. Plain git diff / status / log stay silent as before.

Testing

  • Added Windows regression tests for the cases above.
  • POSIX suite unchanged and passing; tsc --noEmit clean.
  • Verified end-to-end through PolicyEngine on Windows: write-capable git →
    ASK_USER, read-only git → ALLOW.

Related report

Reported to the Google AI VRP:
https://issuetracker.google.com/issues/550750284 - Security Control Bypass in Gemini CLI via git diff --output Flag Injection Leading to Unprompted Arbitrary File Overwrite

I used AI assistance on this, but didn't submit it blindly — I read through the sandbox/policy code, confirmed the root cause, built and reproduced both the vulnerable and fixed behavior locally, and reviewed the diff. Please still verify on your end. Thanks.

@PakCyberbot
PakCyberbot requested a review from a team as a code owner September 3, 2026 12:09
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request strengthens the security of the Windows sandbox by aligning its git command validation logic with the existing POSIX implementation. By centralizing the logic for identifying read-only and dangerous git commands, the system now correctly blocks or flags potentially malicious git operations that were previously treated as safe. This change effectively mitigates a reported security vulnerability related to arbitrary file overwrites via git flag injection.

Highlights

  • Security Fix: Addresses a security vulnerability on Windows where git commands like git diff --output could perform unprompted arbitrary file overwrites by bypassing read-only checks.
  • Code Refactoring: Extracted shared git validation logic into sandbox/utils/commandSafety.ts to ensure consistent security policies between POSIX and Windows environments.
  • Enhanced Validation: Updated Windows sandbox to perform deep inspection of git subcommands and arguments, requiring user confirmation for potentially dangerous flags like --output, --ext-diff, and config overrides.
  • Regression Testing: Added comprehensive test cases in packages/core/src/sandbox/windows/commandSafety.test.ts to verify both safe read-only operations and dangerous write-capable operations.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added the size/m A medium sized PR label Sep 3, 2026
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

📊 PR Size: size/M

  • Lines changed: 188
  • Additions: +123
  • Deletions: -65
  • Files changed: 3

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the git command safety validation logic by extracting it into reusable helper functions (isGitCommandReadOnly and isGitCommandDangerous) and integrating them into the Windows command safety checks, along with adding comprehensive unit tests. However, the review feedback identifies critical security vulnerabilities in both helper functions. Specifically, they fail to validate and block dangerous git global options such as --exec-path, --git-dir, -C, and --work-tree, which could allow an attacker to bypass the sandbox and execute arbitrary commands.

Comment thread packages/core/src/sandbox/utils/commandSafety.ts
Comment thread packages/core/src/sandbox/utils/commandSafety.ts
@gemini-cli gemini-cli Bot added the status/need-issue Pull requests that need to have an associated issue. label Sep 3, 2026
@PakCyberbot

Copy link
Copy Markdown
Author

--exec-path, --git-dir, and -C were already properly validated even before my patch and correctly trigger the permission prompt in Gemini CLI. However, git diff --output /anyloc/anyfile.txt executes without a permission prompt, which can result in the silent destruction of any important file in any location.

proper-validated-except-diffoutput.mp4

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the git command safety checks by extracting the validation logic into shared utility functions (isGitCommandReadOnly and isGitCommandDangerous) and integrating them into the Windows sandbox implementation to ensure cross-platform consistency. The review feedback highlights critical security vulnerabilities where dangerous global git options, such as --exec-path and --git-dir, are not blocked or flagged, potentially leading to Remote Code Execution (RCE) and sandbox escape. Additionally, the reviewer recommends expanding the test suite to cover short-form options like -o to prevent regressions.

Comment thread packages/core/src/sandbox/utils/commandSafety.ts
Comment thread packages/core/src/sandbox/utils/commandSafety.ts
Comment thread packages/core/src/sandbox/windows/commandSafety.ts
Comment thread packages/core/src/sandbox/windows/commandSafety.ts
Comment thread packages/core/src/sandbox/windows/commandSafety.test.ts
Comment thread packages/core/src/sandbox/windows/commandSafety.test.ts
@gemini-cli gemini-cli Bot added area/security Issues related to security and removed status/need-issue Pull requests that need to have an associated issue. labels Sep 4, 2026
@gemini-cli gemini-cli Bot added the priority/p1 Important and should be addressed in the near term. label Sep 6, 2026
@gemini-cli

gemini-cli Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@gemini-cli

gemini-cli Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/security Issues related to security priority/p1 Important and should be addressed in the near term. size/m A medium sized PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: git diff --output bypasses permission prompt, silently overwrites arbitrary files

2 participants