Repository navigation
[DRAFT] feat: add top-level sandbox SDK with Substrate integration - #75
Sunny (sunnylovestiramisu) wants to merge 1 commit into
Conversation
5c64ac4 to
7ad2595
Compare
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
| proc = subprocess.Popen(cmd, cwd=cwd, env=env, stdout=subprocess.PIPE, | ||
| stderr=subprocess.PIPE, start_new_session=True) |
There was a problem hiding this comment.
Command Injection in Subprocess Calls (CWE-78)
Analyzed by AI as
More Details
Detected user input entering a subprocess call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands.
| Attribute | Value |
|---|---|
| Impact | |
| Likelihood |
AI Analysis
The snippet shows subprocess.Popen(cmd, ...) being called, but the source of cmd is not visible in the provided code. Without seeing how cmd is constructed or where it originates from, it's unclear whether user input directly flows into it unsafely. The snippet alone is insufficient to determine if this is exploitable—additional context about cmd's origin is needed to assess the actual injection risk.
Remediation
Command injection vulnerabilities occur when user-supplied input is passed unsanitized to a system command execution function like subprocess.run(). This allows an attacker to execute arbitrary commands on the host system, leading to data theft, malware installation, or full system compromise.
To fix this issue, user input should never be directly passed to command execution functions. Instead, use Python APIs for system operations whenever possible. If you must use subprocess, validate and sanitize all input, and use a whitelist to strictly control allowed commands.
Code examples
# VULNERABLE CODE - User input is passed directly to subprocess.run()
import subprocess
def run_command(user_input):
result = subprocess.run(user_input, shell=True)
return result.stdout# SECURE CODE - Use Python APIs instead of subprocess when possible
import os
def list_files(directory):
return os.listdir(directory)
If you must use `subprocess`, sanitize input and use a whitelist:# SECURE CODE - Whitelist allowed commands and sanitize input
import subprocess
ALLOWED_COMMANDS = ["ls", "grep", "find"]
def run_command(user_input):
if user_input in ALLOWED_COMMANDS:
sanitized_input = [user_input] # Run command directly, no shell
result = subprocess.run(sanitized_input, stdout=subprocess.PIPE)
return result.stdout.decode()
else:
return "Command not allowed"Additional recommendations
- Follow the principle of least privilege and run commands with minimal permissions
- Implement secure coding practices like input validation per OWASP guidelines
- Consider using parameterized APIs or ORMs instead of constructing OS commands
- Perform thorough testing, code review, and penetration testing to identify injection flaws
Rule ID: WS-I013-PYTHON-00058
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
|
We already have a sandbox SDK in the clients directory. What's missing in them? |
7ad2595 to
4090f4c
Compare
For discussion