You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jun 10, 2024. It is now read-only.
Yes, script running is the fundamental of this project. There's a warning on readme that you can setup auth to the task page.
yeah , most people still start pyspider with the default configuration, could force the modification of this default setting ? meanwhile, we also designed such a scene, which is opened in the case of only allowing localhost to access, while supporting JavaScript (using other components for rendering). We use the CSRF method to request the local pyspider to achieve the same effect.
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
🐛 Bug Report
Script content needs security check which could cause RCE
To Reproduce
Expected behavior
the server will execute code what you set(it run with a calc.exe that i set to prove this vuln).
Test script or set of commands reproducing this issue
post this task as follow to server.
Environment
pyspider v0.3.10
system ubuntu 18.04 & windows 10 version1909
The text was updated successfully, but these errors were encountered: