T09 · Insecure Skill Coding Practices
- Location
mask_project.py:151- Finding
Unbounded Evaluation of Attacker-Controlled Regular Expressions
- Content
View full analysis
dict[str, Any]: if not path: return default_policy() policy_path = Path(path).expanduser() data = json.loads(policy_path.read_text(encoding="utf-8")) if not isinstance(data, dict): raise ValueError("Policy must be a JSON object") return data ``` ```python def collect_matches(text: str, policy: dict[str, Any]) -> list[MatchSpan]: matches: list[MatchSpan] = [] for rule in policy.get("rules", []): if not isinstance(rule, dict) or rule.get("type") != "regex": continue label = str(rule.get("label") or "unknown") priority = int(rule.get("priority") or 0) pattern = str(rule.get("pattern") or "") mask_group = rule.get("mask_group") if not pattern: continue compiled = re.compile(pattern, re.MULTILINE) for match in compiled.finditer(text): if mask_group: try: start, end = match.span(str(mask_group)) except IndexError: start, end = match.span() else: start, end = match.span() if start >= 0 and end > start: matches.append(MatchSpan(start=start, end=end, label=label, priority=priority)) return matches ``` ### Technical Analysis The `--policy` option allows a caller to load arbitrary regular-expression patterns from a JSON file. Policy validation verifies high-level fields but does not restrict regex constructs, pattern length, rule count, or execution time. Python's standard `re` engine uses backtracking. A pattern containing nested or ambiguous quantifiers can require exponential processing time when evaluated against a carefu ...[truncated 1594 chars]- Remediation
View remediation
