From abf29df57c8ada9eec1168aa33819740cba565e3 Mon Sep 17 00:00:00 2001 From: Gal Zahavi <38544478+galz10@users.noreply.github.com> Date: Tue, 10 Mar 2026 11:19:49 -0700 Subject: [PATCH] Update packages/cli/src/utils/sandbox.ts Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com> --- packages/cli/src/utils/sandbox.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/packages/cli/src/utils/sandbox.ts b/packages/cli/src/utils/sandbox.ts index 1b138cf4b5..b0e6b296d9 100644 --- a/packages/cli/src/utils/sandbox.ts +++ b/packages/cli/src/utils/sandbox.ts @@ -232,6 +232,7 @@ export async function start_sandbox( const image = config.image; if (!image) throw new FatalSandboxError('Sandbox image is required'); + if (!/^[a-zA-Z0-9_.:/-]+$/.test(image)) throw new FatalSandboxError('Invalid sandbox image name'); const workdir = path.resolve(process.cwd()); const containerWorkdir = getContainerPath(workdir);