Skip to content

🔒 Fix potential argument injection in Process.Start - #267

Open
Dor-bl wants to merge 3 commits into
mainfrom
fix/appium-local-service-argument-injection-6023283297239403583
Open

Dor-bl wants to merge 3 commits into
mainfrom
fix/appium-local-service-argument-injection-6023283297239403583

Conversation

@Dor-bl

@Dor-bl Dor-bl commented Sep 20, 2026

Copy link
Copy Markdown
Owner

🎯 What

Refactored process initialization in AppiumLocalService to pass command line arguments as structured items in ProcessStartInfo.ArgumentList instead of concatenating raw argument strings.

⚠️ Risk

When process arguments are constructed using string concatenation (ProcessStartInfo.Arguments), malicious user-controlled input or capabilities containing spaces, double quotes, or command control characters could lead to argument injection or execution of arbitrary sub-commands.

🛡️ Solution

  • Updated AppiumServiceBuilder to generate discrete argument items (IReadOnlyList<string>).
  • Updated AppiumLocalService to populate process arguments via ProcessStartInfo.ArgumentList (dynamically supported across target frameworks via reflection with a safe fallback for legacy runtimes).
  • Updated OptionCollector to format default capabilities cleanly as a JSON object string without manual quote escaping or shell wrapper quotes.
  • Added unit tests in AppiumLocalServiceTests verifying unquoted argument list construction, special character escaping, and capability JSON formatting.

PR created automatically by Jules for task 6023283297239403583 started by @Dor-bl

@google-labs-jules

Copy link
Copy Markdown

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

Copilot AI lite review requested due to automatic review settings September 20, 2026 07:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The refactor silently changes the documented argument-escaping contract, and the new security tests are excluded from CI.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Refactors Appium process launching to pass structured arguments safely and serialize default capabilities as JSON.

Changes:

  • Builds discrete process argument lists.
  • Uses ArgumentList with escaped fallback handling.
  • Adds argument and capability serialization tests.
File Description
AppiumLocalServiceTests.cs Adds tests for argument construction and JSON formatting.
OptionCollector.cs Serializes capabilities as JSON.
AppiumServiceBuilder.cs Builds structured arguments.
AppiumLocalService.cs Populates process arguments safely.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

argList.Add($"\"{AppiumJS.FullName}\"");
argList.Add("--port");
argList.Add($"\"{Port}\"");
argList.AddRange(NodeOptions);
Comment on lines +185 to +186
[Test]
public void BuildArguments_ConstructsUnquotedArgumentList()
Dor-bl and others added 2 commits September 25, 2026 21:22
Address review feedback on the argument-injection fix:

- WithNodeArguments documents that callers escape values themselves, so
  node options are now appended to the command line verbatim again. Only
  arguments built by the library (Appium JS path, port, address, log file,
  server options, capabilities) are escaped.
- Drop the reflection-based ProcessStartInfo.ArgumentList path. .NET splits
  ProcessStartInfo.Arguments with the same rules on every platform, so one
  escaped command line behaves the same on net48 and net8.0.
- Move the argument tests out of AppiumLocalServiceTests (which needs a
  running Appium server and is not in any CI filter) into a new server-free
  AppiumServiceArgumentsTest fixture, and add it to the unit-test filter.
  Includes an end-to-end check that node receives each argument intact.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants