T09 · Insecure Skill Coding Practices
- Location
scripts/mesh_tool.py:78- Finding
Unbounded Mesh Component Analysis Enables Resource Exhaustion
- Content
View full analysis
Vulnerability Details
File Location:
scripts/mesh_tool.py:78-113
Vulnerability Type: Uncontrolled resource consumption and algorithmic complexity denial of service
Risk Level: MediumVulnerable Code
python def get_components(self): def quantize(v): return (round(v[0], 5), round(v[1], 5), round(v[2], 5)) vertex_map = collections.defaultdict(list) for i, t in enumerate(self.triangles): # t is (v1, v2, v3, id) for v in t[:3]: vertex_map[quantize(v)].append(i) visited_tris = set() components = [] for i in range(len(self.triangles)): if i in visited_tris: continue comp_indices = [] queue = collections.deque([i]) visited_tris.add(i) while queue: curr_idx = queue.popleft() comp_indices.append(curr_idx) curr_tri = self.triangles[curr_idx] for v in curr_tri[:3]: qv = quantize(v) for n_idx in vertex_map[qv]: if n_idx not in visited_tris: visited_tris.add(n_idx) queue.append(n_idx) components.append([self.triangles[idx] for idx in comp_indices]) return componentsTechnical Analysis
The implementation does not enforce limits on STL file size, triangle count, vertex adjacency, component size, memory consumption, or processing time. All parsed triangles are retained in memory, after which
get_components()creates additional collections containing vertex-to-triangle associations, visited triangle indexes, queues, component indexes, and copied component lists.More importantly, each triangle vertex causes the complete list at
vertex_map[qv]to be scanned. An attacker can construct a mesh containing many triangles whose vertices quantize to the same value. IfNtriangles share that value ...[truncated 1801 chars]- Remediation
View remediation
Remediation Suggestions
- Enforce a configurable maximum STL file size before opening or parsing the file.
- Validate the binary triangle count before allocating or reading triangle records, and reject files exceeding a safe maximum.
- Apply equivalent triangle and line limits to the ASCII parser.
- Reject non-finite coordinates such as NaN and infinity.
- Limit the number of triangles associated with a quantized vertex, or abort analysis when adjacency density exceeds a safe threshold.
- Avoid repeatedly scanning duplicate triangle indexes. Build deduplicated neighbor sets or edge-based indexed adjacency once and traverse each relationship only once.
- Avoid copying every triangle into component lists where component indexes or iterators are sufficient.
- Run untrusted mesh analysis in an isolated worker with memory, CPU, execution-time, and process limits.
- Return a controlled validation or resource-limit error when any configured threshold is exceeded.
