Re: git format-patch --in-reply-to allows header injection. Intended?
From: Junio C Hamano <hidden>
Date: 2016-06-15 23:02:26
Niklas Hambüchen [off-list ref] writes:
For example, if you pass "--in-reply-to=<msgid>\nTo: <other@example.com" (notice lack of trailing `>`), then the generated email will actually contain a To: [off-list ref] header.
While I do not think of a reason to specify such a string to the in-reply-to option (I'd rather edit the output in the editor if I wanted to do anything fancy [*1*]), I do not think there is a reason why you want to add a code to forbid such use, either. [Footnote] *1* For that matter, --in-reply-to option itself is superfluous.