The latest released version receives security fixes.
Please report privately rather than in a public issue: open a GitHub security advisory, or email spanio@dei.unipd.it. We aim to acknowledge within a week.
Please include the input file that triggers the problem and the version of lytk.
lytk parses untrusted files (LilyPond, MusicXML, MXL, MIDI, ABC, Humdrum). Bugs reachable from a malicious input file are in scope, in particular:
- panics or unbounded memory/CPU use while parsing (a reachable denial-of-service for any service that converts user uploads)
- path traversal or unintended file reads. The LilyPond readers do not
follow
\include(they report it) unless giveninclude_paths;lytk flatten,lytk.flattenandlytk.flatten_stringdo, by design. An include may name any path, relative (../../x) or absolute, and the file's text becomes part of the output, so callers that follow the includes of untrusted.lytext should run in a sandbox and pass only trusted search paths - decompression bombs in
.mxlarchives (these are read with a size cap)
Release builds keep overflow-checks on, so an integer overflow panics rather
than silently producing corrupt output. Out of scope: crashes from inputs the
caller has already been told are trusted, and resource use proportional to a
legitimately large score.