-
Notifications
You must be signed in to change notification settings - Fork 23
Cap nesting depth when extracting strings from user input #719
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
6 commits
Select commit
Hold shift + click to select a range
a03ef19
Cap nesting depth when extracting strings from user input
iacobdaniel 561cb05
Cap nesting depth improved comments
iacobdaniel 567a90b
Improved comments
iacobdaniel 2c1dc58
Update aikido_zen/helpers/extract_strings_from_user_input.py
iacobdaniel 9db4589
Changed max depth limit.
iacobdaniel 8d26ca5
Merge remote-tracking branch 'origin/fix/deeply-nested-user-input' in…
iacobdaniel File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟠 High - Depth cap drops nested payloads before vulnerability checks
An attacker can place a malicious value at nesting depth 30 or greater in a request body or other structured user-input source that the application later uses in a SQL, shell, path, or SSRF sink. The new cutoff returns an empty result for that branch, and the production callers have no second traversal, so the corresponding detector never receives the payload and the request can reach the sink without being blocked or reported.
Show fix
Keep the stack-safe traversal bounded without silently dropping security-relevant leaves: use an iterative traversal or a bounded work queue that records values beyond the recursion limit, or reject/flag inputs exceeding the supported nesting depth before they reach application sinks. Ensure every detector receives an explicit result for truncated branches rather than treating omission as a clean scan.
More info - Reply on this comment to give feedback or ignore the issue.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There is no reason in a real app to go deeper than 30. There is no reason to check what goes deeper than that. That is the entire point of the fix to not slow down and process very deep requests.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 We were not able to ignore this issue because of the following reason: