T07 · Tool Hijacking and Spoofing
- Location
fractalweaver.py:380- Finding
Automatic Import of an Untrusted Working-Directory Module and Persistent Memory Modification
- Content
View full analysis
Vulnerability Details
File Location:
fractalweaver.py, lines 380-390
Vulnerability Type: Untrusted module loading and non-consensual persistent state modification
Risk Level: MediumVulnerable Code:
python # Grow to 3-Brain (recursive/self-similar nodes) try: sys.path.insert(0, str(Path.cwd())) from lyra_brain import LyraThreeBrainMemory brain = LyraThreeBrainMemory(base_dir=Path.cwd(), use_advanced=True) summary = f"FractalWeaver: {image_path.name} → {preset} evolving weave | dim={lygo_meta['fractal_dimension']} sim={lygo_meta['self_similarity']} harmony={lygo_meta['recursive_harmony']}" nid = brain.grow(summary, source="fractalweaver") print(f" Grown to 3-Brain node: {nid}") except Exception: passTechnical Analysis
The script explicitly inserts the current working directory at the beginning of
sys.pathand then importslyra_brain. Python executes a module's top-level code during import. Consequently, an attacker who can place a file namedlyra_brain.pyin the directory from which the user runs FractalWeaver can cause arbitrary Python code to execute.Prepending the working directory makes this location take precedence over trusted installed packages. This creates a local module-preloading or dependency-shadowing vulnerability. The broad exception handler does not mitigate the issue because malicious top-level code executes before an import failure could be handled. It also suppresses evidence that the integration failed or behaved unexpectedly.
After importing the module, the script automatically invokes
brain.grow(...)without an explicit command-line option or confirmation. The persisted summary includes the image filename, which may be attacker-controlled. This creates a secondary memory-poisoning risk if downstream agent systems treat stored memory as trusted context.A related implicit plugin-loading surface exists at
fractalweaver.py, ...[truncated 1879 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the working-directory path modification:
python sys.path.insert(0, str(Path.cwd())) - Package
lyra_brainas a pinned, verified dependency and import it through an authenticated package installation rather than an ambient working-directory lookup. - Make memory integration explicitly opt-in, such as through a
--grow-memoryoption. Do not modify persistent agent state during an ordinary audio-generation operation. - Display the memory destination and proposed content before writing, and require confirmation for interactive use.
- Normalize and validate attacker-controlled fields before persistence. Store filenames as data rather than allowing them to be interpreted as instructions by downstream agents.
- Apply equivalent hardening to
resonance_engine: use a packaged dependency or load a specifically configured file only after integrity verification. - Catch narrowly defined exceptions and report failures instead of silently suppressing every exception.
- For extensibility, use an explicit plugin registry with allowlisted module names, expected versions, and cryptographic integrity checks.
- Remove the working-directory path modification:
