HF RL Explorer

Command Injection Vulnerability in Command Execution Tools

Command Injection Vulnerability in Command Execution Tools: a task in LegoFlow-SWE (Harbor dataset). The execute command and run command functions accept arbitrary user-provided command strings and pass them directly to subprocess.run() with shell=True without any validation. The documentation…

The task

The `execute_command` and `run_command` functions accept arbitrary user-provided command strings and pass them directly to `subprocess.run()` with `shell=True` without any validation. The documentation promises “no destructive commands” and “no network access unless explicitly allowed,” but these constraints are not…

Part of Lego-X/LegoFlow-SWE.