Skip to content

security: triage 54 audit findings from abandoned clone (#28) - #64

Merged
jacobyoby merged 1 commit into
jacob/maintainedfrom
feature/security-audit-triage-28
Sep 10, 2026
Merged

security: triage 54 audit findings from abandoned clone (#28)#64
jacobyoby merged 1 commit into
jacob/maintainedfrom
feature/security-audit-triage-28

Conversation

@jacobyoby

Copy link
Copy Markdown
Owner

Triaged all 54 security findings from the abandoned docassemble-fix clone.

Triage results:

  • Fixed: 4 (C-5 tar-slip, H-5/H-6 path traversal, M-15 safe_join)
  • Upstream design: 6 (C-1, C-6-C-9, M-17 core engine architecture)
  • Open: 46 findings requiring attention

22 GitHub issues created with security label:

  • 6 critical (PRNG, deserialization, SSRF, etc.)
  • 16 high (auth bypass, injection, etc.)
  • Medium grouped logically
  • 8 low findings consolidated

Stored: .github/SECURITY_AUDIT_TRIAGE.md with full per-finding status.

Closes #28.

Generated with Qwen Code

Cross-referenced each finding against fork commit history:
- 4 fixed (tar-slip, path traversal, open redirects, playground paths)
- 6 upstream design (literal_variables, eval/exec engine, YAML imports)
- 46 open — GitHub issues #29#63 created with security label

Closes #28.
@jacobyoby
jacobyoby merged commit 01ac0b7 into jacob/maintained Sep 10, 2026
3 checks passed
@jacobyoby
jacobyoby deleted the feature/security-audit-triage-28 branch September 10, 2026 06:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Triage the abandoned docassemble-fix clone: security audit, 25 PoC tests, and a dead-guard diff

1 participant