T09 · Insecure Skill Coding Practices
- Location
scripts/data_processor.py:200- Finding
Unsafe Expression Evaluation Allows Python Sandbox Escape
- Content
View full analysis
Any: """ Safe expression evaluation. Supports field references, comparisons, mathematics, logic, and strings. """ safe_dict = {'__builtins__': {}} safe_dict.update(cls.SAFE_FUNCS) safe_dict.update(context) expr = expr.strip() expr = re.sub(r'\bnull\b|\bNone\b', 'None', expr) try: result = eval(expr, safe_dict) return result except Exception as e: raise ValueError(f'Expression parsing failed: {expr} → {e}') ``` ### Technical Analysis The filter and transformation expression is passed directly to Python's `eval()`. Setting `__builtins__` to an empty dictionary is not a security boundary. Python expressions can still perform attribute access and traverse the runtime object graph through existing objects. There is no Abstract Syntax Tree allowlist restricting expressions to arithmetic, comparison, Boolean logic, field references, and approved function calls. Consequently, a crafted expression may access classes or other runtime objects and recover file-access or process-execution primitives. The issue affects every command that routes attacker-controlled expressions through `ExprEvaluator.eval()`, including filtering and data transformation operations. ### Attack Path 1. An attacker supplies a dataset and a malicious filter or transformation expression. 2. The user or Agent invokes a data-processing command with the expression. 3. `ExprEvaluator.eval()` inserts the expression into Python `eval()`. 4. The expression traverses accessible Python objects despite the empty builtins dictionary. 5. The payload obtains a useful runtime primitive and performs unauthorized file access or command execution. 6. The payload runs with the s ...[truncated 457 chars]- Remediation
View remediation
