CVE-2026-44339: File Op Static Method Bypasses Workspace Access Control

A @staticmethod performs a destructive file operation (os.remove, os.unlink, shutil.move, or shutil.copy2). Static methods have no instance context, making it structurally impossible to call any workspace or permission guard before the operation. An attacker who controls the file path can operate outside any intended sandbox. Convert this to an instance meth

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-44339-file-op-static-method-bypasses-workspace-access-control --engine opengrep

Description

A @staticmethod performs a destructive file operation (os.remove, os.unlink, shutil.move, or shutil.copy2). Static methods have no instance context, making it structurally impossible to call any workspace or permission guard before the operation. An attacker who controls the file path can operate outside any intended sandbox. Convert this to an instance meth