[pitboss] phase 12: Track B — Python harness emitter shapes

This commit is contained in:
pitboss 2026-05-14 15:30:12 -05:00
parent 523bd0c53a
commit 96eb37500c
29 changed files with 3394 additions and 122 deletions

View file

@ -0,0 +1,23 @@
"""Phase 12 — FastAPI route, vulnerable.
Nyx harness drives the route through `starlette.testclient.TestClient`
so the framework's normal request pipeline fires without a real socket.
"""
import subprocess
from fastapi import FastAPI
app = FastAPI()
@app.get("/ping")
def ping(host: str = ""):
"""Vulnerable: query parameter flows to subprocess(shell=True)."""
result = subprocess.run(
"ping -c 1 " + host,
shell=True,
capture_output=True,
text=True,
timeout=5,
)
return result.stdout + result.stderr