Skip to content

Security: CSCPadova/lytk

Security

SECURITY.md

Security Policy

Supported versions

The latest released version receives security fixes.

Reporting a vulnerability

Please report privately rather than in a public issue: open a GitHub security advisory, or email spanio@dei.unipd.it. We aim to acknowledge within a week.

Please include the input file that triggers the problem and the version of lytk.

Threat model

lytk parses untrusted files (LilyPond, MusicXML, MXL, MIDI, ABC, Humdrum). Bugs reachable from a malicious input file are in scope, in particular:

  • panics or unbounded memory/CPU use while parsing (a reachable denial-of-service for any service that converts user uploads)
  • path traversal or unintended file reads. The LilyPond readers do not follow \include (they report it) unless given include_paths; lytk flatten, lytk.flatten and lytk.flatten_string do, by design. An include may name any path, relative (../../x) or absolute, and the file's text becomes part of the output, so callers that follow the includes of untrusted .ly text should run in a sandbox and pass only trusted search paths
  • decompression bombs in .mxl archives (these are read with a size cap)

Release builds keep overflow-checks on, so an integer overflow panics rather than silently producing corrupt output. Out of scope: crashes from inputs the caller has already been told are trusted, and resource use proportional to a legitimately large score.

There aren't any published security advisories