Skip to content

Conversation

@florianGla
Copy link
Contributor

A simple guidance hook to nudge Jazzer towards creating FreeMarker
templates with a pattern that can trigger OS command injections.

@florianGla florianGla force-pushed the CIF-1850-freemarker-injection branch 3 times, most recently from 0bf5498 to 367d3bc Compare November 3, 2025 13:35
@florianGla florianGla marked this pull request as ready for review November 3, 2025 13:35
@florianGla florianGla force-pushed the CIF-1850-freemarker-injection branch from 367d3bc to 7823a36 Compare November 3, 2025 13:48
],
)

java_fuzz_target_test(
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this have tags = ["dangerous"] in case it can trigger OS command execution?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you, you are right!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants