[pitboss] phase 12: Track L.10 — Flask / Django / FastAPI / Starlette adapters

This commit is contained in:
pitboss 2026-05-18 11:02:46 -05:00
parent 7509cfe6fd
commit df9fd2bb17
18 changed files with 2042 additions and 9 deletions

View file

@ -0,0 +1,16 @@
"""Phase 12 (Track L.10) — FastAPI CMDI vuln fixture.
`GET /run?cmd=<...>` forwards the `cmd` query parameter straight into
`os.system`. Adapter binding: `@app.get("/run")` with `cmd` flowing
through the function formal.
"""
import os
from fastapi import FastAPI
app = FastAPI()
@app.get("/run")
def run_cmd(cmd: str = ""):
os.system(cmd)
return {"ok": True}