diff --git a/.jules/sentinel.md b/.jules/sentinel.md index 1959a5253..90fc06566 100644 --- a/.jules/sentinel.md +++ b/.jules/sentinel.md @@ -4,3 +4,7 @@ **Vulnerability:** Found an unused `_attempt_import` function in `src/codeweaver/server/mcp/server.py` that dynamically imports a module directly from unvalidated configuration (`import_module(mw.rsplit(".", 1)[0])`), leading to potential arbitrary code execution. **Learning:** Functions that perform dynamic imports should not be left around in the codebase if they are unused, especially if they are designed to take unvalidated strings as input. **Prevention:** Avoid dynamic imports based on configuration or inputs without strict whitelisting. Use tools like `semgrep` with python security rules to actively catch these patterns. +## 2026-04-22 - Arbitrary Code Execution via unvalidated ast.Call in Type Resolution +**Vulnerability:** Found an Arbitrary Code Execution (ACE) vulnerability in `src/codeweaver/core/di/container.py` during dynamic type evaluation via `eval()`. The `TypeValidator` allowed generic `ast.Call` nodes without checking the underlying function being executed, enabling the execution of any callable in the restricted environment's global namespace or provided builtins. +**Learning:** Even when `eval()` is executed with restricted globals and `__builtins__`, allowing `ast.Call` to execute arbitrary functions present in the namespace can lead to unintended code execution. +**Prevention:** Strictly validate and whitelist any `ast.Call` nodes when building restricted execution environments to ensure only explicitly trusted functions (e.g., `Depends`, `Field`) are evaluated. diff --git a/src/codeweaver/core/di/container.py b/src/codeweaver/core/di/container.py index 7cd68ce98..165b7d69e 100644 --- a/src/codeweaver/core/di/container.py +++ b/src/codeweaver/core/di/container.py @@ -84,7 +84,7 @@ def __init__(self) -> None: self._request_cache: dict[Any, Any] = {} # Keys can be types or callables self._providers_loaded: bool = False # Track if auto-discovery has run - def _safe_eval_type(self, type_str: str, globalns: dict[str, Any]) -> Any | None: + def _safe_eval_type(self, type_str: str, globalns: dict[str, Any]) -> Any | None: # noqa: C901 """Safely evaluate a type string using AST validation. Parses the type string into an AST, validates that it contains only safe @@ -130,6 +130,18 @@ def generic_visit(self, node: ast.AST) -> None: ): raise TypeError(f"Forbidden AST node in type string: {type(node).__name__}") + # 🛡️ Sentinel: Mitigate ACE vulnerability by strictly whitelisting allowed ast.Call functions. + if isinstance(node, ast.Call): + func_name = None + if isinstance(node.func, ast.Name): + func_name = node.func.id + elif isinstance(node.func, ast.Attribute): + func_name = node.func.attr + + allowed_funcs = {"Depends", "depends", "Field", "PrivateAttr", "Tag", "Parameter"} + if func_name not in allowed_funcs: + raise TypeError(f"Forbidden function call in type string: {func_name}") + # Block dunder access to prevent escaping the restricted environment if isinstance(node, ast.Name) and node.id.startswith("__"): raise TypeError(f"Forbidden dunder name: {node.id}")