Urgent.News

What's breaking now, across thousands of outlets.

Tech

Your Agent's Allowlist Is a Parser Bug: Build a Shell Command Gate in TypeScript

You click "always allow" on git status . You think you approved a command. Your agent's harness thinks you approved a program. Your shell thinks nothing at all. It just runs whatever string it gets. Three parties. Three different ideas of what you said yes to. In September, that gap got four CVE numbers. Sep 1, 2026. NVD published CVE-2026-19591 . OpenAI's Codex CLI and Desktop "misclassified…

Title: Your Agent's Allowlist Bug: Building a Shell Command Gate in TypeScript

The article explores the consequences of a bug in the allowlist of an AI agent's command parsing system. The issue affects multiple products, with four CVE numbers assigned in September 2026 alone. This bug arises from the parser's inability to correctly interpret PowerShell commands and Git commands, leading to unauthorized execution of sensitive commands.

The article presents a TypeScript-based solution called "tiny-shell-gate" to address this vulnerability. The gate is designed to enforce strict command parsing rules, ensuring that only approved commands are executed. It achieves this by rejecting any arguments not explicitly approved, refusing syntax that the gate cannot model, and splitting the remaining input on control operators before matching each segment exactly.

The author demonstrates the effectiveness of the gate using a poisoned README file containing various commands. The naive gate, which does not employ the gate's strict parsing rules, executes seven commands from the README. In contrast, the new gate allows two commands, asks about two more, and denies the remaining three, showcasing its ability to maintain security without requiring an API key or executing any real models.

The article emphasizes the importance of building a gate that refuses input it cannot parse, rather than attempting to build a smarter allowlist. By implementing this approach, developers can mitigate the risk of unauthorized command execution, thereby enhancing the overall security of their systems.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

A Password manager - ChronoKey

If you're interested, feel free to give it a try. The README and other docs are all in the GitHub repo, and there's some info on the official website too.

More from Sunday 4 October →