mirror of
https://github.com/fusion44/blitz_api.git
synced 2026-08-13 11:52:45 +02:00
Two authenticated code paths interpolated user-controlled input into a shell command: - decode_pay_request passed the bolt11 string into _make_local_call, which ran it via create_subprocess_shell; a crafted /lightning/ decode-pay-req request could execute arbitrary commands. Switch _make_local_call to create_subprocess_exec with a discrete argv list. - blitz_cln_unlock interpolated the wallet password into a cl.hsmtool.sh invocation run through a shell, and logged it in the clear. shlex.quote the interpolated values and mark the call sensitive=True. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| blitz_common.py | ||
| cln_grpc_blitz.py | ||
| cln_jrpc_blitz.py | ||
| README.md | ||
Specializations
Some platforms implement special features on top of the main lightning implementation. This is the place to keep the code for these specializations.
Example: RaspiBlitz implements a specialization for Core Lightning to unlock the wallet.
ℹ️ This keeps dependencies as lean as possible for the main implementations. RaspiBlitz Core Lightning unlock specialization has a redis dependency but the main implementation does not.