Potential Argument Injection Issue in Cygwin's Command Line Handling

Marco Atzeri marco.atzeri@gmail.com
Tue Feb 4 06:57:07 GMT 2025


On 04/02/2025 07:15, Splitline Huang via Cygwin wrote:
> Hello Cygwin team,
> 
> I am splitline from DEVCORE research team. I recently have observed an
> inconsistency
> in how Cygwin handles command-line parsing compared to Microsoft’s
> implementation.
> 
> 
> According to Microsoft’s documentation [1], the \" sequence should always
> be
> interpreted as a literal double quote ("):
>> A double quote mark preceded by a backslash (\") is interpreted as a
> literal
>> double quote mark (").
> 
> However, in Cygwin, the same sequence treats the backslash as a literal
> character
> and starts quote mode instead.
> 

> $ which python
> 
> /cygdrive/c/Python313/python
> 
> splitline@SPLITLINE0D06 ~
> 
> $ python
> 
> Python 3.13.1 (tags/v3.13.1:0671451, Dec  3 2024, 19:06:28) [MSC v.1942
> 
> 64 bit (AMD64)] on win32
> 
> Type "help", "copyright", "credits" or "license" for more information.
> 
>>>> import subprocess
> 
>>>> subprocess.run(['./test.exe', '"', " a b c"]) # should be only 2 args
> 
> argv[0] = ./test
> 
> argv[1] = \
> 
> argv[2] = a
> 
> argv[3] = b
> 
> argv[4] = c
> 
> CompletedProcess(args=['./test.exe', '"', ' a b c'], returncode=0)
> 
>>>>
> 
> 
> 
> As we can see, it should originally be only 2 arguments: ["] and [ a b c].
> However,
> the command line is parsed into 4 different arguments.


$ python3.12
  Python 3.12.8 (main, Jan 31 2025, 21:29:51) [GCC 12.4.0] on cygwin
  Type "help", "copyright", "credits" or "license" for more information.
   import subprocess
   subprocess.run(['./test.exe', '"', " a b c"])
  argv[0] = ./test
  argv[1] = "
  argv[2] =  a b c
  CompletedProcess(args=['./test.exe', '"', ' a b c'], returncode=0)

it seems correct to me for a Cygwin Python

> Note: With that Python code, the spawned command line is: ./test.exe \" " a
> b c"
> 
> Please let me know if you have any questions, thanks!
> 
> Best regards,
> splitline
> DEVCORE

Regards
Marco

PS: Windows is not very consistent on quoting behaviour, e.g.
https://github.com/Azure/azure-cli/blob/dev/doc/quoting-issues-with-powershell.md




More information about the Cygwin mailing list