Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Restrict builtins within lambdas for ImageMath.eval #6009

Merged
merged 1 commit into from
Feb 2, 2022

Conversation

radarhere
Copy link
Member

#5923 (comment) has pointed out that #5923 does not protect against lambdas wrapping unwanted code.

ImageMath.eval("(lambda: exit())()")

I can also imagine a lambda wrapping a lambda.

ImageMath.eval("(lambda: (lambda: exit())())()")

This PR protects against both.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant