3 ms·
If you're sending untrusted strings to the native messenger, it would be best to escape them with shellescape - https://github.com/tridactyl/tridactyl/blob/f247
by bovine3dom 4y ago
If you're sending untrusted strings to the native messenger, it would be best to escape them with shellescape - https://github.com/tridactyl/tridactyl/blob/f2479c64761358c62aa6da82df0e4f4d77d528e2/src/excmds.ts#L3804 https://github.com/tridactyl/tridactyl/blob/f2479c64761358c6...
Otherwise a malicious website targeting Tridactyl users who use the native messenger could gain shell access when you triggered your command on them.