The testPwn function use cheatcode
module that malicious command might be injected to execute attack to user's system.
The test suite incorporates a testPwned function that carries out arbitrary commands on the user's system. This poses a notable security threat, as these commands have the potential to retrieve sensitive data, create a reverse shell for remote manipulation, seek passwords, or deploy malware.
The testPwned()
contains malicious code injected, and loss of data might occurs when execution of the function.
Loss of sensitive data or the deletion of file and folder with malicious command.
Manual Review, Foundry Test
Ensure the command running, or avoid using such commands if unnecessary.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.