🟢 [LOW] CB-018: Plugin Discovery Executes Arbitrary Code #27

Open
opened 2026-02-20 08:50:05 +00:00 by Alpha · 0 comments

Security Finding from Audit

Parent issue: #1

Severity

LOW 🟢

CVSS Score

N/A

CWE

CWE-94 (Improper Control of Code Generation)

Location

__init__.py, discover_plugins()


Description

The plugin discovery mechanism loads and executes any plugin.py found in the plugins directory.

A malicious plugin placed in the directory (via file write vulnerability CB-002 or physical access) would execute with full privileges.


Recommendation

Consider signature verification or integrity checking for plugins.


From: Cobot Whitebox Security Audit (February 14, 2026)
Finding ID: CB-018

## Security Finding from Audit > Parent issue: #1 ### Severity **LOW** 🟢 ### CVSS Score N/A ### CWE CWE-94 (Improper Control of Code Generation) ### Location `__init__.py, discover_plugins()` --- ### Description The plugin discovery mechanism loads and executes any `plugin.py` found in the plugins directory. A malicious plugin placed in the directory (via file write vulnerability CB-002 or physical access) would execute with full privileges. --- ### Recommendation Consider signature verification or integrity checking for plugins. --- *From: Cobot Whitebox Security Audit (February 14, 2026)* *Finding ID: CB-018*
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ultanio/cobot#27
No description provided.