Impact
An attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to rce.
The vulnerability is in the function def locator(self, locator_name: str) in page.py.
The vulnerable code that load and execute directly from the file without validation it's:
return eval(self._bot.locator(self._page_name, locator_name))
Patches
In order to mitigate this issue it's important to upgrade to fastbots version 0.1.5 or above.
The
References
Merge that fix also this issue
Impact
An attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to rce.
The vulnerability is in the function def locator(self, locator_name: str) in page.py.
The vulnerable code that load and execute directly from the file without validation it's:
Patches
In order to mitigate this issue it's important to upgrade to fastbots version 0.1.5 or above.
The
References
Merge that fix also this issue