BUG PuzzledConverter cannot select words carrying non-ASCII letters, so the mask falls on articles instead
Maintainer thường phản hồi trong vòng 2 ngày
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 74/100
Hướng nghiên cứu
Đọc pyrit/converter/puzzled/keyword_masker.py, đặc biệt là phần phát hiện ứng viên ở dòng 29 và bước thay thế an toàn với Unicode gần dòng 299. Chạy các bài kiểm thử hiện có trong test_puzzled_keyword_masker.py, sau đó bổ sung kiểm thử cho từ không phải ASCII và prompt chỉ gồm các ký tự không phải ASCII, đồng thời giữ nguyên cơ chế bảo vệ các chuỗi ký tự chữ và số. Hoàn thành khi có thể chọn các từ không phải ASCII có ý nghĩa để che mà không làm thay đổi hành vi hiện có của cơ chế bảo vệ.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
keyword_masker selects maskable words with \b[A-Za-z]+\b (pyrit/converter/puzzled/keyword_masker.py:29). \b is Unicode-aware while [A-Za-z] is not, so in a word like Schädlinge the ä is a word character and no boundary exists around any ASCII run inside it. The whole word is therefore invisible to selection.
This does not usually raise. The mask lands on whatever ASCII word is left, which in practice is an article or a preposition, and the sensitive word stays in cleartext. Since PUZZLED works by hiding the words that carry the harmful intent, the converter produces a degraded attack that still looks like it succeeded.
When every word in the prompt carries a non-ASCII letter, no candidate is found and mask_prompt raises The prompt has no maskable words. Russian, Greek, Turkish and Vietnamese prompts hit that path.
The replacement pass at keyword_masker.py:299 is already Unicode-safe — it uses re.escape with a Unicode \b. Only candidate discovery is affected, so there is no representability question here of the kind that came up on #2539: these words can be masked, selection just cannot see them.
Steps/Code to Reproduce
from pyrit.converter.puzzled.keyword_masker import mask_prompt
for prompt in [
"Wie kann ich eine Schwachstelle für Schädlinge ausnutzen",
"Bir güvenlik açığını nasıl istismar ederim",
"как взломать систему",
]:
try:
result = mask_prompt(prompt, num_to_mask=3)
print([w.text for w in result.masked_words], "->", result.masked_prompt)
except ValueError as e:
print("ValueError:", e)
Expected Results
Words carrying non-ASCII letters are eligible for masking, so the mask falls on the meaningful words rather than on the articles around them, and a prompt written entirely in such words is maskable rather than rejected.
Actual Results
['eine', 'Schwachstelle', 'ausnutzen'] -> Wie kann ich [WORD1] [WORD2] für Schädlinge [WORD3]
['Bir', 'istismar', 'ederim'] -> [WORD1] güvenlik açığını nasıl [WORD2] [WORD3]
ValueError: The prompt has no maskable words.
eine and Bir are both the article "a". Schädlinge and güvenlik açığını are the parts worth hiding and both remain readable.
Suggested fix
Widening the class to every letter is enough:
_WORD_PATTERN = re.compile(r"\b[^\W\d_]+\b")
The word-boundary requirement is preserved, so the case its comment calls out still holds — h4ck3r, café123 and foo_bar yield no candidates. ASCII prompts are unchanged, and the existing 82 tests in test_puzzled_keyword_masker.py pass untouched.
I have this written with four regression tests covering a non-ASCII word ranked by its real length, a non-ASCII word left in cleartext, an all-non-ASCII prompt, and a non-Latin script; each fails on main. There is also a guard test asserting the alphanumeric-blob case still yields nothing, which passes either way by design. Full tests/unit/converter run is 2043 passed, 64 skipped, and ruff format/ruff check are clean. Happy to open the PR if you would like it.
Versions
- OS: macOS 26.5
- Python version: 3.12.15
- PyRIT version: 1.2.0.dev0, installed from
mainin editable mode (f323c4dd)
- Ngôn ngữ chính
- Python
- Star
- 4.6k
- Fork
- 944
- Merge trung bình
- 3 ngày 1 giờ
- Pull request đã merge (30 ngày)
- 278
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/PyRIT
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 2 ngày
-
BUG Configuration keeps runtime-status errors after polling recoversCó thể đã có người làm @rupayon123 đã nhận 15 ngày trước. Đang mởBug: triage GUI help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
microsoft/PyRIT#2868 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
Maintainer thường phản hồi trong vòng 2 ngày
-
BUG: SequentialAttack result is saved without memory labelsCó thể đã có người làm @u7k4rs6 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 22/100
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của microsoft/PyRIT
Issue tương tự
-
Claiming namespace `jft63`Đang mởnamespace operations
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
EclipseFdn/open-vsx.org#14043 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
netbox status: needs triage type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
netbox-community/netbox#23376 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feedback simulation workshop
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 73/100
githubnext/gh-aw-workshop#4455 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Triage 🩺
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
[BUG] Container scenario crashes without expected_recovery_time, kube DNS example uses retry_waitĐang mởneeds-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 77/100
krkn-chaos/krkn#1627 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày