| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Fixes ship in a new release rather than as patches to earlier versions.
If you discover a security vulnerability:
-
Do NOT create a public GitHub issue
-
Open a private report: https://github.com/kkdev92/clipshot/security/advisories/new
That is the Report a vulnerability button in the repository's Security tab; the link goes straight to it. Private reporting is enabled, so the advisory stays between us until there is a fix to describe.
This extension implements the following security measures:
All shell commands are executed using:
- Base64 Encoding for PowerShell (
-EncodedCommand) - Proper Escaping for Unix shells
- Environment Variables for parameter passing
// Safe PowerShell execution
const encoded = encodePowerShellCommand(script);
const cmd = `powershell.exe -EncodedCommand ${encoded}`;- The saved image, and every folder created for it, is checked to be inside the workspace before it is written
realpath()resolves symbolic links in the part of the path that already exists, so a link cannot lead the image outside the workspace- A save directory that leads outside the workspace, through
..or otherwise, is refused when the image is saved. One whose..stays inside the workspace resolves to the folder it names
// Path validation (src/security/path-validator.ts, simplified)
const realRoot = await fs.realpath(workspaceRoot);
const realTarget = await resolveExistingPrefix(targetPath, workspaceRoot);
const relative = path.relative(realRoot, realTarget);
if (relative.startsWith('..') || path.isAbsolute(relative)) {
throw new PathValidationError('Path is outside the workspace');
}- Cryptographically random file names (
crypto.randomBytes) - Exclusive file creation (
O_EXCLflag) - Automatic cleanup
- Restricted permissions (
0o600)
Settings are checked each time they are read:
- Numeric values are clamped to valid ranges, and a value of the wrong type falls back to the default
- A save directory that is absolute or contains
.., and a file name pattern with shell metacharacters, are reported as configuration warnings in the ClipShot log. They are not what keeps writes inside the workspace; the check above is - Each generated file name has control characters, and the characters a Windows file name cannot hold (
< > : " / \ | ? *), removed. On Windows, a reserved name such asCONis prefixed
The extension requires a trusted workspace and will not operate in untrusted workspaces.
- Review Save Directory: Ensure
saveDirectoryis set to a reasonable location - Check File Permissions: Saved images have standard permissions
- Network Access: This extension does not make any network requests
- Clipboard Access: The extension only reads clipboard data when you explicitly trigger the paste command
- On Windows, PowerShell execution is required for clipboard access
- The extension cannot validate the content of images for malicious data
- Symbolic link resolution depends on filesystem support