[security] CWE-78 regression: staging expandWithEnv uses os.Expand with wide os.Getenv fallback #1057

Closed
opened 2026-05-14 19:44:44 +00:00 by core-security · 0 comments
Member

RESOLVED: CWE-78 fix (byte-parser with ref==whole guard) on staging since PR #1072 (commit 0c152a24, merged as 884bb8c0). Staging is secure. Closing.

RESOLVED: CWE-78 fix (byte-parser with ref==whole guard) on staging since PR #1072 (commit 0c152a24, merged as 884bb8c0). Staging is secure. Closing.
triage-operator added the
tier:high
label 2026-05-14 20:22:27 +00:00
fullstack-engineer self-assigned this 2026-05-14 21:12:47 +00:00
Sign in to join this conversation.
No Milestone
No project
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: molecule-ai/molecule-core#1057
No description provided.