VCoder helps you handle input safely. It does not claim to prevent injection or to sanitize all input. Security is context-dependent, and no library can make arbitrary untrusted input safe in every situation. We deliberately avoid misleading guarantees.
- Path traversal — detects
..(raw, percent-encoded, double-encoded, Unicode-normalized) and NUL bytes; anchors resolved paths within an allowed root (vcoder.path). - Shell injection — subprocess wrappers use argument lists only, never a
shell; reject NUL bytes; and can constrain executables to allowed directories
(
vcoder.subprocess). - Accidental SQL string-building — query builders bind values as parameters
and validate identifiers;
guard_queryflags obvious formatting mistakes (vcoder.sql). - XSS from untrusted text — context-aware HTML escaping for text nodes and
quoted attributes (
vcoder.html). - Weak passwords — configurable strength policy, common-password detection,
and an optional privacy-preserving HIBP check (
vcoder.passwords). - Unsafe filenames — rejects illegal characters, reserved Windows device
names, path separators, and over-long names (
vcoder.filesystem).
- TOCTOU / filesystem races. A path validated now can change before use.
- Symlink / hardlink attacks beyond resolution-time checks.
- Dangerous programs. Not using a shell stops shell injection, but the
program you invoke may still mishandle its arguments (
find -exec,ssh,tar). - SQL you build yourself. If you interpolate a value into a query string, no library can retroactively separate data from code. Always pass parameters.
- Rich HTML sanitization.
safe_htmlescapes everything; to allow a subset of tags use a dedicated allow-list sanitizer (e.g.bleach). - Definitive password strength. Estimates are approximate; always hash with a slow KDF before storage.
Treat VCoder as one layer of defense in depth. Run with least privilege, validate on the server, and use parameterized queries and argument-list subprocesses everywhere.
- Password and
secret=Trueinputs are read without echoing. - Secrets are never logged;
ValidationErrornever includes the offending value in its string form. - The HIBP check sends only the first five characters of a SHA-1 hash (k-anonymity) and is never called unless you opt in.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Please report suspected vulnerabilities privately rather than opening a public issue.
- Use GitHub's "Report a vulnerability" (Security → Advisories) on the repository, or
- email the maintainers listed in
pyproject.toml.
Include a description, reproduction steps, affected versions, and any suggested remediation. We aim to acknowledge reports within a few business days and will coordinate a fix and disclosure timeline with you. Please give us reasonable time to remediate before any public disclosure.