From d1574273c9ced4f4831be5bc8e396ab65bf66a56 Mon Sep 17 00:00:00 2001 From: Anurag Kumar Singh Date: Tue, 8 Sep 2026 11:36:28 +0530 Subject: [PATCH 1/2] Making insecure=true for curl.get conditional based on OS --- lua/platformio/piolib.lua | 2 +- lua/platformio/utils.lua | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/lua/platformio/piolib.lua b/lua/platformio/piolib.lua index e59b8af..c8e7da4 100644 --- a/lua/platformio/piolib.lua +++ b/lua/platformio/piolib.lua @@ -17,7 +17,7 @@ function M.piolib(lib_arg_list) local url = 'https://api.registry.platformio.org/v3/search' local res = curl.get(url, { - insecure = true, + insecure = utils.is_windows, -- Windows curl builds often lack a CA bundle, breaking TLS verification timeout = 20000, headers = { content_type = 'application/json' }, query = { diff --git a/lua/platformio/utils.lua b/lua/platformio/utils.lua index ed32498..bc7b5cd 100644 --- a/lua/platformio/utils.lua +++ b/lua/platformio/utils.lua @@ -20,14 +20,14 @@ function M.check_prefix(str, prefix) end ------------------------------------------------------ -local is_windows = jit.os == 'Windows' +M.is_windows = jit.os == 'Windows' -M.devNul = is_windows and ' 2>./nul' or ' 2>/dev/null' +M.devNul = M.is_windows and ' 2>./nul' or ' 2>/dev/null' -- INFO: get current OS enter function M.enter() local shell = vim.o.shell - if is_windows then + if M.is_windows then return vim.fn.executable('pwsh') and '\r' or '\r\n' elseif shell:find('nu') then return '\r' From c33dad14e10b3ddbcba6578e166236e74ec8f5f1 Mon Sep 17 00:00:00 2001 From: Anurag Kumar Singh Date: Tue, 8 Sep 2026 11:46:58 +0530 Subject: [PATCH 2/2] Added sanitize_shell_arg to prevent any possiblity of command injection while using Piolib and Pioinit --- lua/platformio/pioinit.lua | 4 +++- lua/platformio/piolib.lua | 4 ++-- lua/platformio/utils.lua | 4 ++++ 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/lua/platformio/pioinit.lua b/lua/platformio/pioinit.lua index 6cee0d3..881a002 100644 --- a/lua/platformio/pioinit.lua +++ b/lua/platformio/pioinit.lua @@ -9,7 +9,9 @@ local function init_project(board_details, selected_framework) if framework == 'none' then framework = '' end - local command = 'pio project init --board ' .. board_details.id .. ' --project-option "framework=' .. framework .. '"' + local board_id = utils.sanitize_shell_arg(board_details.id) + local framework_arg = utils.sanitize_shell_arg(framework) + local command = 'pio project init --board ' .. board_id .. ' --project-option "framework=' .. framework_arg .. '"' utils.ToggleTerminal(command, 'float', function() vim.cmd(':PioLSP') boilerplate_gen(framework) diff --git a/lua/platformio/piolib.lua b/lua/platformio/piolib.lua index c8e7da4..4fde684 100644 --- a/lua/platformio/piolib.lua +++ b/lua/platformio/piolib.lua @@ -32,8 +32,8 @@ function M.piolib(lib_arg_list) if res['status'] == 200 then local json_data = vim.json.decode(res['body']) picker.pick_library(json_data.items or {}, function(selected_library) - local owner = (selected_library.owner and selected_library.owner.username) or '' - local name = selected_library.name or '' + local owner = utils.sanitize_shell_arg((selected_library.owner and selected_library.owner.username) or '') + local name = utils.sanitize_shell_arg(selected_library.name or '') if owner == '' or name == '' then vim.notify('Invalid library selection: missing owner or name.', vim.log.levels.ERROR) return diff --git a/lua/platformio/utils.lua b/lua/platformio/utils.lua index bc7b5cd..b2fe69e 100644 --- a/lua/platformio/utils.lua +++ b/lua/platformio/utils.lua @@ -19,6 +19,10 @@ function M.check_prefix(str, prefix) return str:sub(1, #prefix) == prefix end +function M.sanitize_shell_arg(str) + return (str or ''):gsub('[^%w%.%-_/]', '') +end + ------------------------------------------------------ M.is_windows = jit.os == 'Windows'