Skip to content

Settings POST endpoint accepts unvalidated/unbounded JSON body #4

Description

@carochacs

Found during a security audit.

Where: my-plugin/routes.py:60-98, set_settings

Issue: No size/type limit on the POSTed JSON body or its values — _DEFAULTS keys aren't schema-validated, so a client can stuff arbitrarily large strings/nested structures into settings, or add unbounded extra keys, all merged and written to disk. No request body size cap either — await request.json() buffers an arbitrarily large POST body into memory before any validation.

Impact: Since this is the scaffold new plugins are cloned from, this pattern gets copy-pasted into every new plugin — worth fixing here specifically because of that multiplier, even though each individual instance is low-severity.

Suggested fix: Add a schema/type check on the settings body and a reasonable size cap (e.g. via a request size limit middleware or explicit length check) before persisting.

Metadata

Metadata

Labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions