CVE-2026-44339: File Op Static Method Bypasses Workspace Access Control
A @staticmethod performs a destructive file operation (os.remove, os.unlink, shutil.move, or shutil.copy2). Static methods have no instance context, making it structurally impossible to call any workspace or permission guard before the operation. An attacker who controls the file path can operate outside any intended sandbox. Convert this to an instance meth
greprules fetch cve-2026-44339-file-op-static-method-bypasses-workspace-access-control --engine opengrepDescription
A @staticmethod performs a destructive file operation (os.remove, os.unlink, shutil.move, or shutil.copy2). Static methods have no instance context, making it structurally impossible to call any workspace or permission guard before the operation. An attacker who controls the file path can operate outside any intended sandbox. Convert this to an instance meth
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.