#694 APP-01: No resource limits on app child processes

closed critical Created 2025-12-25 02:56 · Updated 2025-12-25 03:03

Description

Edit
Location: executor.py:462. Issue: multiprocessing.Process spawned without CPU/memory/file descriptor limits. Malicious or buggy app can fork bomb, consume all memory, or open unlimited handles. Fix: Use resource.setrlimit before exec or migrate apps to Docker sandbox (sandbox.py exists).

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...