Skip to content

Protect read-from-string from readtime code execution #43

Description

@vindarel

The full Lisp reader is in effect when we use read-from-string, so anything could happen and using it can lead to vulnerabilities issues. Example:

(read-from-string "#.(print \"you're dead!\")")
;; => "you're dead!"

;; compare with:
(read-from-string "(print \"you're dead!\")")
;; => (PRINT "you're dead")
;; => the PRINT was not executed.

Don't use it with input coming from the outside. That being said, it is possible to disable the #. reader macro:

(let ((cl:*read-eval* nil))
  (read-from-string "…"))
;; => #<SB-INT:SIMPLE-READER-ERROR "can't read #. while *READ-EVAL* is NIL" {10091A1663}>.

and better, to use a standard readtable and prevent other reader macros:

(with-standard-io-syntax
  (let ((cl:*read-eval* nil))
    (read-from-string "…")))

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions