From 422ffedc32c31fef39d943612d7e738cf4ad5e23 Mon Sep 17 00:00:00 2001 From: Xi Lu Date: Sat, 18 Feb 2023 18:03:28 +0800 Subject: [PATCH] * lisp/ob-latex.el (org-babel-execute:latex): Fix command injection vulnerability. --- lisp/ob-latex.el | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lisp/ob-latex.el b/lisp/ob-latex.el index 428907a27..c32e7ea4c 100644 --- a/lisp/ob-latex.el +++ b/lisp/ob-latex.el @@ -180,7 +180,7 @@ This function is called by `org-babel-execute-src-block'." tmp-pdf (list org-babel-latex-pdf-svg-process) extension err-msg log-buf))) - (shell-command (format "mv %s %s" img-out out-file))))) + (shell-command (format "mv %s %s" (shell-quote-argument img-out) (shell-quote-argument out-file)))))) ((string-suffix-p ".tikz" out-file) (when (file-exists-p out-file) (delete-file out-file)) (with-temp-file out-file -- 2.30.2