Dangerous chain: exec() wrapping compile
- Category
- Dangerous Code Execution
- Confidence
- 99% confidence
- Finding
The script reads Python source from gen_board.py, slices part of it, then compiles and executes it with exec(). That means any code placed in the so-called data layer of gen_board.py will run when generating Excel, turning a report-generation helper into an arbitrary code execution path if the sibling file is modified, replaced, or supplied from an untrusted source.
- Content
python raise SystemExit("data-layer marker not found in gen_board.py") _data_src = _src.split(MARK)[0] ns = {} exec(compile(_data_src, "gen_board_data", "exec"), ns) PROJECTS = ns["PROJECTS"]; SUPPLIERS = ns["SUPPLIERS"]; QUOTES = ns["QUOTES"] TERMS = ns["TERMS"]; CLAR = ns["CLAR"]; TRANS_NOTE = ns["TRANS_NOTE"]
