Harden subprocess argv against option injection (#2)

- download.py: insert `--` before URL in yt-dlp argv so a `-`-prefixed
  string can never be parsed as a flag (e.g. --exec, --config-location).
  Tighten is_url to reject `-`-prefixed sources and require non-empty
  netloc.
- frames.py, whisper.py: resolve video/audio paths to absolute via
  Path.resolve() before passing to ffmpeg/ffprobe (which don't honor
  `--` as end-of-options), so a relative path starting with `-` can
  never be misinterpreted as a flag.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
bradautomates
2026-05-09 08:13:32 +10:00
parent 755c157466
commit 3c488688d1
3 changed files with 8 additions and 5 deletions
+2 -2
View File
@@ -66,7 +66,7 @@ def get_metadata(video_path: str) -> dict:
"-print_format", "json",
"-show_format",
"-show_streams",
video_path,
str(Path(video_path).resolve()),
],
capture_output=True,
text=True,
@@ -162,7 +162,7 @@ def extract(
cmd += ["-to", f"{end_seconds:.3f}"]
cmd += [
"-i", video_path,
"-i", str(Path(video_path).resolve()),
"-vf", f"fps={fps},scale={resolution}:-2",
"-frames:v", str(max_frames),
"-q:v", "4",