Skip to content

Conversation

lociko
Copy link

@lociko lociko commented Sep 29, 2025

Issue #, if available:

Description of changes:

Amazon Q CLI does not properly validates the usage of the find command. While the code attempts to block dangerous options like -exec, -ok, -delete, and -fprint, it overlooks -fls, which can write arbitrary file listings to attacker-controlled paths. This can lead to arbitrary file creation or overwrite in sensitive directories.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lociko
Copy link
Author

lociko commented Oct 3, 2025

Any updates?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant