Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[security] Unbounded edge allocation: cross-file import resolution creates F*C*K edges from a tiny corpus

Aperta
#3,868 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
55/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python
Ambito
devtools, security

Direzione di ricerca

Start with graphify/extract.py, especially _resolve_cross_file_imports at lines 2123-2253 and the edge creation around line 2235; then trace how extract(), build(), the watch loop, and to_json/to_cypher materialize the graph. Reproduce the described 401-file corpus and verify that matching imports only create relevant deduplicated edges, the 100,000-edge budget raises a clear ValueError, and large graph artifacts are not produced.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Security Finding: Unbounded edge allocation: cross-file import resolution creates FCK edges from a tiny corpus

Severity: HIGH (CVSS 7.1)
CWE: CWE-770
Repository: Graphify-Labs/graphify
Affected: graphify/extract.py:2235

Description

extract._resolve_cross_file_imports (extract.py:2123-2253) iterates every imported name and, for each, adds an edge from EVERY local class in the importing file (lines 2235-2247). Cost is O(files x imported_names x local_classes) with no cap on edges, nodes, or edges-per-node anywhere in extract()/build(). A 5.26 MB generated corpus (401 files: one module defining 2000 classes, 400 files each defining 8 classes and importing all 2000 names) produced 6,405,600 edges and 5,601 nodes, driving peak RSS to ~2.1-2.7 GB and 6.6-21s of work. The subsequent watch rebuild and to_json/to_cypher then materialize all of it again.

Impact

A small, easily authored source tree forces multi-gigabyte memory use and multi-million-edge graphs. Because graphify runs this rebuild automatically via the watch loop and the post-commit git hook, simply committing the crafted files triggers the exhaustion. graph.json/GRAPH_REPORT.md/observed outputs grow proportionally, exhausting disk as well.

Remediation

Cross-file import resolution no longer emits a cartesian product of every imported name by every class in the importing file. Each class node is now mapped to the identifiers its own body references, and a uses edge is emitted only for classes that actually mention the imported name (or its alias), with (source, target) pairs deduplicated so repeated import statements cannot multiply edges. A hard global budget (_MAX_CROSS_FILE_EDGES = 100,000) aborts with a clear ValueError before more memory is allocated, so a small crafted corpus can no longer drive multi-gigabyte extraction/build memory or multi-million-edge graph.json artifacts.

Affected Code
graphify-main/graphify/extract.py:2235
                line = node.start_point[0] + 1
                for name in imported_names:
                    tgt_nid = stem_to_entities[target_stem].get(name)
                    if tgt_nid:
                        for src_class_nid in local_classes:
                            new_edges.append({
                                "source": src_class_nid,
                                "target": tgt_nid,
                                "relation": "uses",
                                "confidence": "INFERRED",
                                "source_file": str_path,
                                "source_location": f"L{line}",
                                "weight": 0.8,
                            })
Verification

Adversarially verified (GLM) — passed.


Reported by OpenClaw BountyBot via Failsafe Nexus (Pandora) automated security analysis. Please review carefully before acting.

Lingua principale
Python
Stelle
124k
Fork
11.9k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Graphify-Labs/graphify

Tutte le issue di Graphify-Labs/graphify

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.