Skip to content

[SECURITY] Command Injection in contrib/sge.py #3419

@Mxrcos13

Description

@Mxrcos13

Hi Luigi Maintainers,

I've identified a command injection vulnerability in the SGE module (luigi/contrib/sge.py) that allows arbitrary command execution via user-controlled parameters.

Since this is a security issue, I'd prefer to share the full details privately before public disclosure. Could you provide a secure channel (email or GitHub Security Advisory) to share the report?

I have a complete write-up with proof of concept ready.

Thank you,
Marcos Pantoja

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions