安全性: helpers::tokenizeCommand 中的命令允许列表通过双引号中的命令替换进行绕过

作者: Pcmhacker-piro创建于 2026年9月11日更新于 2026年9月11日

Describe the bug A security flaw in helpers::tokenizeCommand (helpers.cpp) allows arbitrary command execution that bypasses commandAllowList when double quotes are used.

内容来源: neutralinojs/neutralinojs