harden: detected non-static command inside open3 in... - #901
Conversation
Detected non-static command inside Open3 Addresses ruby.lang.security.dangerous-exec.dangerous-exec
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
|
Semgrep says HIGH; the real severity is none. Three independent reasons:
|
|
Thanks for the detailed explanation. I agree that the Open3.capture3 multi-argument form does not invoke a shell, so the original command-injection finding was a false positive on this call site. I also agree that an attacker who can arbitrarily control MESHTASTIC_PYTHON already has a much stronger level of access than this check would protect against. The executable-path validation could still be useful as general configuration hardening, but I agree it shouldn’t be presented as a fix for the reported command-injection issue. |
Summary
Harden input handling in
web/lib/potato_mesh/application/meshtastic/payload_decoder.rb(flagged by semgrep).Vulnerability
ruby.lang.security.dangerous-exec.dangerous-execweb/lib/potato_mesh/application/meshtastic/payload_decoder.rb:45Description: Detected non-static command inside Open3.capture3. Audit the input to 'Open3.capture3'. If unverified user data can reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary code.
Threat Model Context
This is a containerized service - vulnerabilities may be exploitable depending on network exposure.
Changes
web/lib/potato_mesh/application/meshtastic/payload_decoder.rbBehavior Preservation
The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.
Security Invariant
Regression test
This test guards against regressions — it's useful independent of the code change above.
This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.
Automated security fix by OrbisAI Security