T09 · Insecure Skill Coding Practices
- Location
scripts/math_calculator.py:128- Finding
Unbounded Exponentiation Allows Resource-Exhaustion Denial of Service
- Content
View full analysis
Vulnerability Details
File Location:
scripts/math_calculator.py, lines 128-133 and 151-159
Vulnerability Type: Uncontrolled resource consumption through unrestricted exponentiation
Risk Level: MediumThe evaluator exposes both the exponentiation operator and the built-in
powfunction to untrusted mathematical expressions without limiting exponent size, operand size, expression length, AST depth, execution time, or memory consumption.Relevant operator mapping:
python SAFE_OPERATORS = { ast.Add: operator.add, ast.Sub: operator.sub, ast.Mult: operator.mul, ast.Div: operator.truediv, ast.Mod: operator.mod, ast.Pow: operator.pow, }Relevant function mapping:
python SAFE_FUNCTIONS = { 'sin': math.sin, 'cos': math.cos, 'tan': math.tan, 'asin': math.asin, 'acos': math.acos, 'atan': math.atan, 'sinh': math.sinh, 'cosh': math.cosh, 'tanh': math.tanh, 'log': math.log10, 'ln': math.log, 'log2': math.log2, 'sqrt': math.sqrt, 'abs': abs, 'floor': math.floor, 'ceil': math.ceil, 'round': round, 'exp': math.exp, 'pow': pow, }Vulnerable binary-operation execution:
python elif isinstance(node, ast.BinOp): left = self._visit(node.left) right = self._visit(node.right) op_type = type(node.op) if op_type in SAFE_OPERATORS: return SAFE_OPERATORS[op_type](left, right) raise ValueError(f"Unsupported operator: {op_type.__name__}")Vulnerable function-call execution:
python elif isinstance(node, ast.Call): # Only allow predefined functions if isinstance(node.func, ast.Name): func_name = node.func.id.lower() if func_name in self.functions: args = [self._visit(arg) for arg in node.args] return self.functions[func_name](*args) raise ValueError ...[truncated 2429 chars]- Remediation
View remediation
Remediation Suggestions
- Enforce a strict maximum input length before parsing the expression.
- Traverse the AST before evaluation and reject trees exceeding configured node-count or nesting-depth limits.
- Add a dedicated exponentiation handler instead of mapping
ast.Powdirectly tooperator.pow. - Reject exponents whose absolute value exceeds a conservative threshold appropriate for the calculator's intended use.
- Reject integer operands and intermediate results exceeding a configured bit-length limit.
- Remove the built-in
powfunction fromSAFE_FUNCTIONS, or wrap it with the same operand and exponent checks. - Apply bounds to other potentially expensive functions and operations, including nested expressions.
- Run calculations in a separate worker process with operating-system or container-level CPU, memory, and wall-clock limits. Terminate the worker when a deadline is exceeded.
- Return a controlled validation error when an expression exceeds any complexity or numeric-size limit.
- Add regression tests for oversized exponents, nested powers, excessive AST depth, and excessive input length.
