char ssh_user[512] in transport_ssh.c:121 is used with snprintf for user@host. The code checks needed >= sizeof(ssh_user) and prints a warning but continues execution with a truncated string. The execvp("ssh", ...) call will use the truncated user@host, potentially connecting to the wrong host or user, or failing mysteriously.
Location
src/shared/transport_ssh.c:121-128
How to trigger
Specify a very long username or hostname in the SSH destination (e.g., user@very.long.hostname.that.exceeds.512.bytes.example.com:/path). The local buffer truncates the string silently.
Suggested Fix
Use dynamically allocated buffer with asprintf() or malloc() + snprintf() instead of the fixed 512-byte stack buffer. Fail with an error message on truncation rather than continuing with truncated data.
Severity
medium
Category
security
Sub-Agent
security-screener (SC-4)
This issue was automatically generated by the issue-creator agent.
## Description
`char ssh_user[512]` in `transport_ssh.c:121` is used with `snprintf` for `user@host`. The code checks `needed >= sizeof(ssh_user)` and prints a warning but continues execution with a truncated string. The `execvp("ssh", ...)` call will use the truncated user@host, potentially connecting to the wrong host or user, or failing mysteriously.
## Location
src/shared/transport_ssh.c:121-128
## How to trigger
Specify a very long username or hostname in the SSH destination (e.g., `user@very.long.hostname.that.exceeds.512.bytes.example.com:/path`). The local buffer truncates the string silently.
## Suggested Fix
Use dynamically allocated buffer with `asprintf()` or `malloc()` + `snprintf()` instead of the fixed 512-byte stack buffer. Fail with an error message on truncation rather than continuing with truncated data.
## Severity
medium
## Category
security
## Sub-Agent
security-screener (SC-4)
---
_This issue was automatically generated by the issue-creator agent._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
char ssh_user[512]intransport_ssh.c:121is used withsnprintfforuser@host. The code checksneeded >= sizeof(ssh_user)and prints a warning but continues execution with a truncated string. Theexecvp("ssh", ...)call will use the truncated user@host, potentially connecting to the wrong host or user, or failing mysteriously.Location
src/shared/transport_ssh.c:121-128
How to trigger
Specify a very long username or hostname in the SSH destination (e.g.,
user@very.long.hostname.that.exceeds.512.bytes.example.com:/path). The local buffer truncates the string silently.Suggested Fix
Use dynamically allocated buffer with
asprintf()ormalloc()+snprintf()instead of the fixed 512-byte stack buffer. Fail with an error message on truncation rather than continuing with truncated data.Severity
medium
Category
security
Sub-Agent
security-screener (SC-4)
This issue was automatically generated by the issue-creator agent.
Fixed in PR #148 — merged into main on 2026-07-29. See #148