{"record":{"id":"f8298c656db85ae6","repo":"Tencent/WeKnora","slug":"argument-injection-detected","errorCode":null,"errorMessage":"argument injection detected","messagePattern":"argument injection detected","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/sandbox/sandbox.go","lineNumber":107,"sourceCode":"\tDefaultCubeHTTPTimeout = 30 * time.Second\n\n\t// DefaultE2BSandboxTTL matches the E2B SDK's built-in default so an\n\t// unset E2BSandboxTTL still yields a valid sandbox lifetime.\n\tDefaultE2BSandboxTTL = 5 * time.Minute\n\t// DefaultE2BHTTPTimeout bounds a single HTTP call to the E2B API.\n\tDefaultE2BHTTPTimeout = 30 * time.Second\n)\n\n// Common errors\nvar (\n\tErrSandboxDisabled   = errors.New(\"sandbox is disabled\")\n\tErrTimeout           = errors.New(\"execution timed out\")\n\tErrScriptNotFound    = errors.New(\"script not found\")\n\tErrInvalidScript     = errors.New(\"invalid script\")\n\tErrExecutionFailed   = errors.New(\"script execution failed\")\n\tErrSecurityViolation = errors.New(\"security validation failed\")\n\tErrDangerousCommand  = errors.New(\"script contains dangerous command\")\n\tErrArgInjection      = errors.New(\"argument injection detected\")\n\tErrStdinInjection    = errors.New(\"stdin injection detected\")\n)\n\n// Sandbox defines the interface for isolated script execution\ntype Sandbox interface {\n\t// Execute runs a script in an isolated environment\n\tExecute(ctx context.Context, config *ExecuteConfig) (*ExecuteResult, error)\n\n\t// Cleanup releases sandbox resources\n\tCleanup(ctx context.Context) error\n\n\t// Type returns the sandbox type\n\tType() SandboxType\n\n\t// IsAvailable checks if the sandbox is available for use\n\tIsAvailable(ctx context.Context) bool\n}\n","sourceCodeStart":89,"sourceCodeEnd":125,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/sandbox/sandbox.go#L89-L125","documentation":"Sentinel ErrArgInjection returned by the sandbox manager when argument-injection patterns are detected in the script or its arguments (manager.go:151), or when the provider result flags injection. It prevents crafted inputs from injecting flags/options into the executed command line.","triggerScenarios":"Thrown at internal/sandbox/sandbox.go:107 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Escape or quote user-supplied values before embedding them in script arguments","Pass untrusted data via stdin/env vars instead of command-line arguments","Strip or reject argument-separating characters (--, ;, |, backticks) from inputs","Do not retry unchanged; fix the input sanitization first"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}