Skip to content

Deny access to some classes in js evaluator, deny host access in python evaluator#1057

Merged
c4lm merged 6 commits intomainfrom
restrict-graalvm-evaulators
May 5, 2026
Merged

Deny access to some classes in js evaluator, deny host access in python evaluator#1057
c4lm merged 6 commits intomainfrom
restrict-graalvm-evaulators

Conversation

@c4lm
Copy link
Copy Markdown
Contributor

@c4lm c4lm commented Apr 29, 2026

Pull Request type

  • Bugfix

Changes in this PR

This PR denies access to java classes used for RCE.

Alternatives considered

Denying host access is likely not an option right now. I think we will do better sandboxing once we deprecate graalvm so that there are no scripts relying on java classes being available.

@c4lm c4lm requested review from nthmost-orkes and v1r3n April 29, 2026 19:45
@c4lm c4lm merged commit 87a7d96 into main May 5, 2026
5 checks passed
@c4lm c4lm deleted the restrict-graalvm-evaulators branch May 5, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants