Dangerous chain: eval() wrapping compile
- Category
- Dangerous Code Execution
- Confidence
- 95% confidence
- Finding
The code evaluates rule formulas from JSON files using eval(compile(...)) after only a partial AST allowlist check. Although builtins is removed and names are constrained, this still creates a code-execution surface on untrusted or tampered rule content and relies on a brittle custom sandbox that may be bypassed now or in future edits. In a local CAD-processing skill that loads all JSON rules from a directory, this is especially risky because attackers who can modify rule files can influence execution during analysis.
- Content
python raise ValueError(f"公式使用了未知变量:{node.id}") ns = dict(namespace) ns.update(_SAFE_FUNCS) return eval(compile(tree, "<rule>", "eval"), {"__builtins__": {}}, ns) def apply_rule(rule: dict[str, Any], member: dict[str, Any], profile: dict[str, list[str]],
