Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Security] Arbitrary code execution through unrestricted DLL scanning in PluginDiscovery

Open
#4 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
csharp
Domain
backend, security

Research direction

Start in Plugins/FluentCMS.Infrastructure.Plugins/Discovery/PluginDiscovery.cs, focusing on the Scan() method and its use of ScanAssemblyPatterns, Assembly.GetExecutingAssembly().Location, and Environment.ProcessPath. Review how plugin loading and IPluginStartup execution work, then define which directory configuration and assembly verification approach will be adopted; done means matching DLLs are not loaded from the host output directory without the selected trust checks.

Written by the indexing model from the issue text.

Description

bug security

Summary

PluginDiscovery.Scan() resolves the scan path from Assembly.GetExecutingAssembly().Location / Environment.ProcessPath and enumerates all *.dll files in the application's output directory that match ScanAssemblyPatterns (default: FluentCMS.Plugins.*). Any DLL placed in that directory will be loaded and executed with the application's full trust level on next startup.

Location

Plugins/FluentCMS.Infrastructure.Plugins/Discovery/PluginDiscovery.cs — Scan() method (~line 42)

Risk

A supply-chain or filesystem-level attacker can drop a malicious DLL matching the naming pattern and have arbitrary code execute at application startup. There is no:

  • File signature / hash verification
  • Allowlist of trusted publishers (Authenticode)
  • Sandbox or isolated execution

Reproduction

  1. Build the host application.
  2. Copy a malicious DLL named FluentCMS.Plugins.Evil.dll into the output directory.
  3. Restart the application — the DLL is discovered, loaded, and any IPluginStartup implementation executes.

Recommendation

  1. Allow operators to configure an explicit, out-of-tree plugin directory instead of defaulting to the host binary directory:
    options.PluginDirectory = "/opt/myapp/plugins"; // separate from binaries
    
  2. Optionally add file hash verification or Authenticode certificate validation before loading each assembly.
  3. Consider a plugin allowlist (name + expected hash) stored in a protected configuration location.

Severity

🔴 Critical / Security

Dominant language
C#
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from fluentcms/FluentCMS.Infrastructure

All issues in fluentcms/FluentCMS.Infrastructure

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.