Skip to content

[AW Top 10] 09 Close the custom grader sandbox escape #67454

Description

@github-actions

Priority 9/10 | 1 source issues | Impact 4/5 | Confidence 4/5 | Effort 3/5

One assignment, one coherent fix

The inline JavaScript grader runs user scripts in a node vm context, which is not a security boundary and was reported escapable.

Implementation scope

Run inline graders in a separate restricted process or worker without inherited capabilities, and drop reliance on the source blocklist.

Done when

  • The reported proof of concept no longer executes a command.
  • A test asserts a grader cannot reach process or require.

Why now

The report includes a runnable proof of concept and the current code still uses vm.createContext, so the risk is plausible. Exposure depends on who can author graders.

AW source issues and corroborating reports

#66044

No corroborating AW discussion; evidence comes from the source issues.

Unchanged AW sources close only after this summary is completed. Newer source activity and not-planned retirement do not trigger source closure. Assigned summaries are frozen; unassign to allow reclustering.

Generated by AW Essential Issue Clustering · copilot · auto · 40.1 AIC · ⌖ 0.589 AIC · ⊞ 8.9K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

agentic-workflowsautomationaw-essentialEssential AW-generated issue clusters: assign one to resolve related findingscookieIssue Monster Loves Cookies!

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions