mirror of
https://gitee.com/mirrors/ohmyzsh.git
synced 2026-09-29 14:29:46 +08:00
The `omz_urldecode` function uses an eval to decode the input which can be exploited to inject commands. This is used only in the svn plugin and it requires a complex process to exploit, so it is highly unlikely to have been used by an attacker.