Files
twenty/packages/twenty-sdk/src/cli
Charles Bochet adb60a3867 fix(sdk): avoid shell command injection in CLI exec calls (#21508)
## What

Fixes the 5 open [CodeQL code-scanning
alerts](https://github.com/twentyhq/twenty/security/code-scanning) of
type `js/shell-command-constructed-from-input` (medium severity) in the
`twenty-sdk` CLI.

All flagged call sites built a shell command string by interpolating
library inputs (`containerName`, `image`, `npmTag`) and ran it via
`execSync`, which executes through a shell. A value containing shell
metacharacters could break out of the intended command.

## Changes

- `packages/twenty-sdk/src/cli/utilities/server/docker-container.ts` —
every `docker` call switched from `execSync` with a template string to
`execFileSync('docker', [...args])`. Arguments are passed as an array,
so the binary runs directly without a shell and inputs are never
reparsed. The single quotes that were shell-quoting the `-f` format
strings are removed since there is no shell.
- `packages/twenty-sdk/src/cli/operations/publish.ts` — `npm publish`
switched to `execFileSync` with `--tag`/value as separate array
elements. On Windows the binary resolves to `npm.cmd` (no shell to do
the lookup).

## Verification

- `npx nx typecheck twenty-sdk` passed
- `npx nx lint twenty-sdk` passed

<!-- This is an auto-generated description by cubic. -->
<a
href="https://cubic.dev/pr/twentyhq/twenty/pull/21508?utm_source=github"
target="_blank" rel="noopener noreferrer"
data-no-image-dialog="true"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img
alt="Review in cubic"
src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a>
<!-- End of auto-generated description by cubic. -->
2026-06-12 22:40:08 +02:00
..
2026-05-20 15:12:39 +00:00