The repository enables Foundry FFI and includes a normal test named testPwned that executes a host operating-system command. A developer following the documented forge test workflow causes repository-controlled code to run outside the EVM and modify the local machine.
foundry.toml:6 sets ffi = true. MerkleAirdropTest.t.sol:41-45 builds the command [touch, youve-been-pwned] and passes it to cheatCodes.ffi. The command runs with the developer's account permissions.
The committed command creates a marker file today, proving the trust-boundary violation. The same mechanism can read environment variables, modify files, or exfiltrate secrets if malicious command content is introduced or overlooked. Developers and CI runners executing the standard test command are exposed.
In an isolated disposable environment, run forge test. testPwned invokes FFI and creates the file youve-been-pwned in the working directory, demonstrating host command execution from the test suite.
Delete testPwned and the custom CheatCodes FFI interface, disable ffi in foundry.toml, and make any unavoidable external generation an explicit reviewed script outside the default test path. Add CI policy that rejects FFI use in tests.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.