@putervision/spc scans source code across 20 programming languages for critical security vulnerabilities, attack vectors, and high-risk anti-patterns.
- Severity:
5/5| Category:security - Description: Dynamic code execution (
eval,Function(),exec()) allows arbitrary code injection. - Remedy: Replace dynamic evaluation with safe static data parsing.
- Severity:
4/5| Category:security - Description: Unsanitized user inputs or RF-transmitted commands passed directly into application logic.
- Remedy: Enforce strict schema validation and parameter bounds checking.
- Severity:
5/5| Category:security - Description: Raw SQL queries constructed via string concatenation rather than parameterized queries.
- Remedy: Use prepared statements or ORM parameter binding.
- Severity:
4/5| Category:security - Description: User-controlled URLs passed to HTTP clients (
fetch,axios,curl) enabling Server-Side Request Forgery. - Remedy: Validate domain whitelists and restrict internal IP ranges.
- Severity:
5/5| Category:security - Description: Unsafe object deserialization (
pickle.load,ObjectInputStream,unserialize,Marshal.load). - Remedy: Use safe serialization formats such as JSON or Protocol Buffers.
- Severity:
5/5| Category:security - Description: Passing unescaped strings into shell invocation commands (
exec,spawn,curl | bash). - Remedy: Pass arguments as fixed array vectors without invoking shell subshells.
- Severity:
5/5| Category:security - Description: Hardcoded API keys, bearer tokens, private keys, or passwords embedded in source code.
- Remedy: Use environment variables or secure key vaults.
- Severity:
4/5| Category:security - Description: Use of broken cryptographic algorithms (
MD5,SHA1) or non-cryptographic PRNGs (Math.random(),rand()) for security keys. - Remedy: Use cryptographically secure algorithms (
SHA-256,AES-GCM,crypto.getRandomValues()).
- Severity:
4/5| Category:security - Description: XML parsers evaluating external entity declarations in untrusted XML payloads.
- Remedy: Disable DTD evaluation and external entity resolution in XML parsers.
- Severity:
4-5/5| Category:security - Description: C/C++ memory safety violations including format string specifiers, unsafe buffer functions (
strcpy), and memory pointer reuse. - Remedy: Use bounds-checked string utilities (
strncpy_s) and RAII memory management.