clearpathrobotics / robot_upstart

ROS package of helper functions related to bringing up roslaunch on system startup.
BSD 3-Clause "New" or "Revised" License
196 stars 96 forks source link

scripts/mutate_files possible security issue #90

Open bucan3ve opened 4 years ago

bucan3ve commented 4 years ago

Hi,

During some security audit activities i encountered robot_upstart and I've spotted a vulnerability in the mutate_files script: it is possible for a user to give as input a malicious pickle to the script which is then executed. I won't spoil more details for security reasons, so feel free to contact me if you want more details.

mail: leox14@protonmail.com