blitz_api/tests
fusion44 4355c8eabd
fix(lightning): prevent shell injection in CLN local calls
Two authenticated code paths interpolated user-controlled input into a
shell command:

- decode_pay_request passed the bolt11 string into _make_local_call,
  which ran it via create_subprocess_shell; a crafted /lightning/
  decode-pay-req request could execute arbitrary commands. Switch
  _make_local_call to create_subprocess_exec with a discrete argv list.
- blitz_cln_unlock interpolated the wallet password into a
  cl.hsmtool.sh invocation run through a shell, and logged it in the
  clear. shlex.quote the interpolated values and mark the call
  sensitive=True.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-03 19:58:41 +02:00
..
models feat: implement Ruff as a linter; fix given errors 2023-06-25 07:17:00 +02:00
routers tests: add better integration tests 2026-02-03 11:06:06 +01:00
__init__.py test: Add testing dependencies and first tests 2021-10-02 12:00:44 +02:00
test_cln_shell_safety.py fix(lightning): prevent shell injection in CLN local calls 2026-07-03 19:58:41 +02:00
test_warmup_events.py fix: send bitcoin-only warmup app status as app_state_update_message 2026-07-03 15:30:17 +02:00
utils.py chore: format source using the pre_commit command 2022-03-20 17:20:56 +01:00