Skip to content

Fix command-injection in network monitor (use execFile) and add tests - #14

Closed
rtrappman-dev wants to merge 1 commit into
masterfrom
codex/find-critical-security-or-functional-issues
Closed

rtrappman-dev wants to merge 1 commit into
masterfrom
codex/find-critical-security-or-functional-issues

Conversation

@rtrappman-dev

Copy link
Copy Markdown
Owner

Motivation

  • Network monitoring commands interpolated policy-controlled targets into shell strings, creating a command-injection risk for ping/dig/curl invocations.
  • The change aims to remove shell interpretation of untrusted values and preserve existing monitoring behavior and metrics collection.

Description

  • Replace inline shell pipelines in sensor/NetworkMonitorSensor.js with a safe command boundary that calls a new helper util/NetworkMonitorCommand.js which uses execFile and passes every user-controlled value as an argument.
  • Implement ping, dns, and http helpers in util/NetworkMonitorCommand.js that run sudo ping, dig, and curl respectively and parse the timing output without invoking a shell.
  • Add -- when invoking curl and validate that DNS/HTTP/ping targets are supplied as literal arguments to prevent option or shell injection.
  • Add regression tests in test/test_network_monitor_security.js that assert payloads containing shell metacharacters are passed as single literal arguments and validate the parsing behavior.

Testing

  • Ran unit tests npx mocha --exit test/test_network_monitor_security.js, which passed (2 passing).
  • Performed syntax checks with node -c on sensor/NetworkMonitorSensor.js and util/NetworkMonitorCommand.js, both succeeded.
  • Ran git diff --check to confirm no whitespace/patch issues; no problems found in the working tree.
  • ESLint was not executed in this environment because the repository’s lint binaries were not available here, so linting remains to be run in CI or locally.

Codex Task

@rtrappman-dev
rtrappman-dev deleted the codex/find-critical-security-or-functional-issues branch September 8, 2026 02:43
@rtrappman-dev
rtrappman-dev restored the codex/find-critical-security-or-functional-issues branch September 8, 2026 03:11
@rtrappman-dev
rtrappman-dev deleted the codex/find-critical-security-or-functional-issues branch September 8, 2026 03:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant