Ability to execute arbitrary commands on user device
The ffi
cheatcode is enable in foundry.toml
file, which can execute arbitrary commands on the user's machine.
This presents a significant security risk, as such commands could potentially extract sensitive data, establish a reverse shell for remote control, search for passwords, or install malware.
MEDIUM. HIgh risk for the user, but currently no scripts are executed in tests. Still a security risk.
Manual review.
Remove ffi = true
from foundry.toml
file
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.