Skip to content

Vulnerability in plugin_only mode

Low
ShilinHe published GHSA-922q-hvcv-p99w Mar 25, 2024

Package

No package listed

Affected versions

cc1dadca3f49394d7f65285f49169338d34fbb9d

Patched versions

3817ab733c21c07ebd6c8005cef6a7df4708e906

Description

Impact

We added the plugin_only mode from PR 180.
This mode was intended for users only want to call the plugins without generating any code.
However, a malicious user is able to violate the plugin_only mode using injection attacks.
This issue affects all versions of TaskWeaver before the PR 250 if the plugin_only mode is enabled. This issue will not have any effect if the user is not enabling the plugin_only mode.
We recommend all users to upgrade to the latest version of TaskWeaver to avoid this issue.

Patches

This issue is addressed in PR 250.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs