#324 CRITICAL: App versioning does not isolate code - all tenants run whatever code is on disk

closed critical Created 2025-12-09 05:45 · Updated 2025-12-10 01:48

Description

Edit
App version system gives FALSE sense of isolation. Workers load code from disk via importlib, ignoring version metadata. Evidence: tenant on v1.0.0 (wrong URL) ran successfully after file edited on disk. Impact: no version isolation, security risk, audit/compliance failure. Root cause: executor.py uses importlib.import_module() from disk, not version-specific storage.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...