mirror of
https://github.com/neovim/neovim.git
synced 2026-07-31 04:39:07 +00:00
Problem: [security]: arbitrary code execution via keyword lookup in
sh.vim, zsh.vim and ps1.vim filetype plugin
(manus-use)
Solution: For powershell, quote the commands using single quotes, for
sh/zsh pass the argument as a separate list item to term_start()/system()
(Yasuhiro Matsumoto).
Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2
c5a82fe013
Co-authored-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
48 lines
1.5 KiB
VimL
48 lines
1.5 KiB
VimL
" Vim filetype plugin file
|
|
" Language: Zsh shell script
|
|
" Maintainer: Christian Brabandt <cb@256bit.org>
|
|
" Previous Maintainer: Nikolai Weibull <now@bitwi.se>
|
|
" Latest Revision: 2026 Jul 23
|
|
" License: Vim (see :h license)
|
|
" Repository: https://github.com/chrisbra/vim-zsh
|
|
|
|
if exists("b:did_ftplugin")
|
|
finish
|
|
endif
|
|
let b:did_ftplugin = 1
|
|
|
|
let s:cpo_save = &cpo
|
|
set cpo&vim
|
|
|
|
setlocal comments=:# commentstring=#\ %s formatoptions-=t formatoptions+=croql
|
|
|
|
let b:undo_ftplugin = "setl com< cms< fo< "
|
|
|
|
if get(g:, 'zsh_fold_enable', 0)
|
|
setlocal foldmethod=syntax
|
|
let b:undo_ftplugin .= "fdm< "
|
|
endif
|
|
|
|
if executable('zsh') && &shell !~# '/\%(nologin\|false\)$'
|
|
if exists(':terminal') == 2
|
|
command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', <q-args>])
|
|
elseif has("patch-9.2.0250")
|
|
command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', <q-args>])
|
|
endif
|
|
setlocal keywordprg=:ZshKeywordPrg
|
|
let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg'
|
|
|
|
if !exists('current_compiler')
|
|
compiler zsh
|
|
endif
|
|
let b:undo_ftplugin .= ' | compiler make'
|
|
endif
|
|
|
|
let b:match_words = '\<if\>:\<elif\>:\<else\>:\<fi\>'
|
|
\ . ',\<case\>:^\s*([^)]*):\<esac\>'
|
|
\ . ',\<\%(select\|while\|until\|repeat\|for\%(each\)\=\)\>:\<done\>'
|
|
let b:match_skip = 's:comment\|string\|heredoc\|subst'
|
|
|
|
let &cpo = s:cpo_save
|
|
unlet s:cpo_save
|