From e094a89a6cc6dcc085e3c4f42af544eb30cb8baf Mon Sep 17 00:00:00 2001 From: "Chaunte W. Lacewell" Date: Thu, 10 Sep 2026 10:39:40 -0700 Subject: [PATCH] Potential fix for code scanning alert no. 2: Uncontrolled command line Refer to [Security issue](https://github.com/IntelLabs/Video-Curation-Sample/security/code-scanning/2). Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- video/info.py | 1 + video/utils.py | 7 ++++--- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/video/info.py b/video/info.py index f17ecde..087e617 100755 --- a/video/info.py +++ b/video/info.py @@ -34,6 +34,7 @@ def _get_info(self, video): "-count_frames", "-show_streams", "-i", + "--", input_path, ] with Popen( diff --git a/video/utils.py b/video/utils.py index 20ab543..2628366 100644 --- a/video/utils.py +++ b/video/utils.py @@ -34,13 +34,14 @@ def validate_video_name(name): raise ValueError("Video name cannot be empty") # Disallow path separators to ensure this is just a file name. if os.sep in cleaned or "/" in cleaned or "\\" in cleaned: + raise ValueError(f"Invalid video name: {cleaned}") # Restrict the video name to a safe subset of characters to avoid # passing arbitrary strings to external commands. # Allow letters, digits, underscore, hyphen and dot, and disallow - # leading dot to avoid hidden or special files. - if cleaned.startswith("."): + # leading dot and leading hyphen to avoid hidden/special files and + # command option injection. + if cleaned.startswith(".") or cleaned.startswith("-"): raise ValueError(f"Invalid video name: {cleaned}") if not re.fullmatch(r"[A-Za-z0-9._-]+", cleaned): raise ValueError(f"Invalid video name: {cleaned}") - raise ValueError(f"Invalid video name: {cleaned}") return cleaned