Skip to content

BashTool input validation security hardening #7478

Description

@RinZ27

The BashTool currently allows some potentially unsafe shell syntax to pass through command parsing. We need to harden the input validation to prevent command injection and ensure a safer execution environment.

Specific improvements needed:

  • Validate command names against invalid characters.
  • Detect and block dangerous shell syntax like pipelines and redirections during parsing.
  • Ensure the execution environment is sane.

Activity

  1. github-actions commented on Jan 9, 2026

    @github-actions
    Contributor

    This issue might be a duplicate of existing issues. Please check:

    While #7474 addresses permission enforcement for subagents, it's related to the overall security hardening of bash/tool execution. Feel free to ignore if this doesn't address your specific case.

  2. RinZ27 commented on Jan 9, 2026

    @RinZ27
    Author

    Thanks for the heads up. Reviewed #7474, but this issue focuses specifically on input validation and sanitization for the BashTool itself, whereas #7474 deals with permission enforcement layers. Proceeding with this as a separate task.

  3. github-actions commented on Mar 25, 2026

    @github-actions
    Contributor

    To stay organized issues are automatically closed after 90 days of no activity. If the issue is still relevant please open a new one.

  4. RinZ27 commented on Mar 26, 2026

    @RinZ27
    Author

    @thdxr bumping this so the bot doesn't auto-close it. BashTool's input validation is still worth looking into, and I'd be happy to help out if you're tied up with other tasks. Just let me know if you want me to take a pass at it.

  5. RinZ27 commented on Mar 26, 2026

    @RinZ27
    Author

    Implemented the requested security hardening for BashTool in PR #19290.

    The implementation now strictly validates input to prevent command injection and ensures a sane execution environment. I also updated the test suite to match these new security constraints. everything is green on my end.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions