Harden subprocess argv against option injection (#2)
- download.py: insert `--` before URL in yt-dlp argv so a `-`-prefixed string can never be parsed as a flag (e.g. --exec, --config-location). Tighten is_url to reject `-`-prefixed sources and require non-empty netloc. - frames.py, whisper.py: resolve video/audio paths to absolute via Path.resolve() before passing to ffmpeg/ffprobe (which don't honor `--` as end-of-options), so a relative path starting with `-` can never be misinterpreted as a flag. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
+2
-2
@@ -66,7 +66,7 @@ def get_metadata(video_path: str) -> dict:
|
||||
"-print_format", "json",
|
||||
"-show_format",
|
||||
"-show_streams",
|
||||
video_path,
|
||||
str(Path(video_path).resolve()),
|
||||
],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
@@ -162,7 +162,7 @@ def extract(
|
||||
cmd += ["-to", f"{end_seconds:.3f}"]
|
||||
|
||||
cmd += [
|
||||
"-i", video_path,
|
||||
"-i", str(Path(video_path).resolve()),
|
||||
"-vf", f"fps={fps},scale={resolution}:-2",
|
||||
"-frames:v", str(max_frames),
|
||||
"-q:v", "4",
|
||||
|
||||
Reference in New Issue
Block a user