Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: high
Invalid

FFI enabled by default

Summary

Arbitrary commands could be run leading to security risks for user running the test suite.

Vulnerability Details

The test suite have a testPwned that use ffi which allow to execute an arbitrary command on the user machine.
It can lead to security risks.

Impact

Potential malicious arbitrary commands run.

Tools Used

Manual review

Recommendations

Deactivate ffi by default. Run tests inside in an isolated environment.

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

testPwned: ffi enabled for test

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Out of scope

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.