T09 · Insecure Skill Coding Practices
- Location
scripts/analyzer.py:160- Finding
Untrusted Regular Expression Enables Application Crash and CPU Denial of Service
- Content
View full analysis
list[str]: results = [] for source in ALLOWED_SOURCES: logs = get_logs(source, lines) for line in logs: if re.search(pattern, line, re.IGNORECASE): results.append(sanitize(f"[{source}] {line}")) ``` The pattern originates directly from the command-line argument: ```python parser.add_argument("--search", help="Search pattern (regex)") ... results = search_logs(args.search, args.last) ``` ### Technical Analysis The value supplied through `--search` is passed directly to Python's backtracking regular-expression engine. There is no pattern validation, complexity restriction, length limit, compilation error handling, or execution timeout. An invalid expression, such as an unmatched parenthesis, raises an uncaught `re.error` and terminates the analyzer. A valid expression containing catastrophic backtracking can consume excessive CPU when evaluated against a sufficiently long log entry. Because log content can be influenced by applications and their external inputs, an attacker may be able to place a string in a whitelisted log that maximizes the cost of a malicious or inadvertently unsafe search expression. The pattern is evaluated separately against every retrieved line from every configured source, amplifying its resource consumption. ### Attack Path 1. An attacker or untrusted caller supplies a crafted pattern through `--search`, or induces an Agent to invoke the analyzer with that pattern. 2. For an immediate crash, the caller provides syntactically invalid regex input such as `(`. 3. For CPU exhaustion, the caller provides a catastrophic-backtracking expression and ensures or identifies a long, non-matching line in one of the whitelisted logs ...[truncated 531 chars]- Remediation
View remediation
