T09 · Insecure Skill Coding Practices
- Location
scripts/calculator.py:39- Finding
Unbounded Mathematical Expression Evaluation Enables Resource Exhaustion
- Content
View full analysis
Vulnerability Details
File Location:
scripts/calculator.py, lines 39-43 and 66-74
Vulnerability Type: Uncontrolled resource consumption through unrestricted mathematical operations
Risk Level: MediumVulnerable Code:
python 'pow': pow, 'max': max, 'min': min, 'pi': math.pi, 'e': math.e,python 'factorial': math.factorial, 'gcd': math.gcd,python code = compile(expr, '<string>', 'eval') # Check for disallowed names for name in code.co_names: if name not in allowed_names: return {"error": f"Unknown function or variable: {name}"} result = eval(code, {"__builtins__": {}}, allowed_names)Technical Analysis
The evaluator restricts accessible names and removes built-ins, which mitigates straightforward arbitrary code execution. However, it compiles and evaluates a user-controlled expression without enforcing limits on expression length, integer magnitude, exponent size, factorial arguments, nesting depth, execution time, memory consumption, or result size.
Allowed operations such as
pow,factorial, exponentiation, and arbitrary-precision integer arithmetic can require excessive CPU time or memory. Name allowlisting does not prevent this class of attack because the resource-intensive operations are intentionally exposed. Exception handling only applies after Python raises an exception; it does not provide a time limit or protect the process from operating-system termination caused by memory exhaustion.Attack Path
- An attacker submits a computationally expensive calculator expression, such as an extremely large factorial or integer exponent.
- The Agent invokes the documented command:
bash python3 scripts/calculator.py calc "<attacker-controlled expression>" compile()acce ...[truncated 1041 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace direct evaluation of compiled input with an AST-based expression interpreter that explicitly permits only required numeric literals, operators, and function calls.
- Reject expressions exceeding a small maximum input length and enforce limits on AST node count and nesting depth.
- Limit integer literal length, numeric magnitude, exponent values, and factorial arguments before performing calculations.
- Reject non-finite values and cap the magnitude and serialized size of results.
- Execute calculations in an isolated worker process with strict wall-clock timeout, CPU, and memory limits. Terminate the worker when a limit is exceeded.
- Add tests for denial-of-service inputs, including very large factorials, exponents, deeply nested expressions, oversized literals, and expressions with many operations.
- Return a generic limit-related JSON error when an input exceeds an enforced constraint rather than attempting the calculation.
