v1.4.461

danielmiessler/Fabricv1.4.461Jul 28, 2026by github-actions[bot]

AI Summary

The extension executor has been hardened to prevent command injection attacks by ensuring all user-controlled values are properly shell-escaped before execution.

Key Highlights

  • Shell-escaped extension values to prevent command injection
  • Wrapped user-controlled values in single quotes with embedded escaping
  • Added regression test to verify malicious input is rejected

Full Release Notes

## Changes

### PR [#2152](https://github.com/danielmiessler/Fabric/pull/2152) by [AUTHENSOR](https://github.com/AUTHENSOR): fix: shell-escape extension values to prevent command injection

- **Fix:** Shell-escape extension values to prevent command injection in the extension executor, which previously ran commands via `sh -c` with unescaped, user-controlled values interpolated into the command string. All user-controlled values are now wrapped in single quotes with embedded-single-quote escaping prior to interpolation, ensuring the shell treats them as literal arguments. A regression test (`ShellInjectionBlocked`) has been added to verify that malicious input (e.g., `hello; touch /marker`) does not execute unintended shell commands.