WhisperX tag archive

#pty.spawn

This page collects WhisperX intelligence signals tagged #pty.spawn. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-28 20:54:13 · GitHub Issues

1. Terminal Lifecycle Handler Faces Shell-Injection Audit Over Unsafe Command Interpolation

Security researchers have identified a shell-injection vulnerability pathway in the terminal command template used across the codebase. The issue centers on a shell-script string built for `pty.spawn` that directly interpolates user-controlled values — including worktree paths, branch names, and agent prompts — without...