[Security] Arbitrary code execution through unrestricted DLL scanning in PluginDiscovery
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start in Plugins/FluentCMS.Infrastructure.Plugins/Discovery/PluginDiscovery.cs, focusing on the Scan() method and its use of ScanAssemblyPatterns, Assembly.GetExecutingAssembly().Location, and Environment.ProcessPath. Review how plugin loading and IPluginStartup execution work, then define which directory configuration and assembly verification approach will be adopted; done means matching DLLs are not loaded from the host output directory without the selected trust checks.
Written by the indexing model from the issue text.
Description
Summary
PluginDiscovery.Scan() resolves the scan path from Assembly.GetExecutingAssembly().Location / Environment.ProcessPath and enumerates all *.dll files in the application's output directory that match ScanAssemblyPatterns (default: FluentCMS.Plugins.*). Any DLL placed in that directory will be loaded and executed with the application's full trust level on next startup.
Location
Plugins/FluentCMS.Infrastructure.Plugins/Discovery/PluginDiscovery.cs — Scan() method (~line 42)
Risk
A supply-chain or filesystem-level attacker can drop a malicious DLL matching the naming pattern and have arbitrary code execute at application startup. There is no:
- File signature / hash verification
- Allowlist of trusted publishers (Authenticode)
- Sandbox or isolated execution
Reproduction
- Build the host application.
- Copy a malicious DLL named
FluentCMS.Plugins.Evil.dllinto the output directory. - Restart the application — the DLL is discovered, loaded, and any
IPluginStartupimplementation executes.
Recommendation
- Allow operators to configure an explicit, out-of-tree plugin directory instead of defaulting to the host binary directory:
options.PluginDirectory = "/opt/myapp/plugins"; // separate from binaries - Optionally add file hash verification or Authenticode certificate validation before loading each assembly.
- Consider a plugin allowlist (name + expected hash) stored in a protected configuration location.
Severity
🔴 Critical / Security
- Dominant language
- C#
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from fluentcms/FluentCMS.Infrastructure
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 48/100
All issues in fluentcms/FluentCMS.Infrastructure
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
PCL-Community/PCL-CE#3652 ·
Maintainers usually reply within 1 day
-
area:frontend bug FE P3
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
klasolsson81/jobbliggaren#2010 ·
Maintainers usually reply within 1 day
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
area: homeblaze type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
RicoSuter/Namotion.Interceptor#630 ·
Maintainers usually reply within 1 day
-
Akka.Hosting enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 65/100