lov-finder-action
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyAnomalyreferences/applescript-iterm.swift
LOWAnomalyLOW
references/applescript-iterm.swift
This code is designed to open Terminal/iTerm and execute a `cd` to a provided directory by generating and executing AppleScript. While the intended behavior is benign and no clear exfiltration or persistence is present, it uses a high-sensitivity execution primitive (`NSAppleScript.executeAndReturnError`) with only partial escaping of untrusted input. If `path` can be attacker-influenced, it presents a plausible AppleScript/shell command injection risk in the user’s Terminal/iTerm session. Strong input validation/allowlisting or safer APIs (avoiding AppleScript command injection) are recommended.
Confidence: 62%Severity: 60%
Audit Metadata