원클릭으로
recursion-dos
Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Generate polished, human-sounding vulnerability disclosure reports for GHSA, HackerOne, and email. Auto-selects channel, calculates CVSS, and adapts tone.
Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
Detect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.
Cross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.
| name | recursion-dos |
| description | Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits. |
| metadata | {"filePattern":["**/*.js","**/*.ts","**/*.py","**/*.go"],"bashPattern":["grep.*(recursive|recurse|depth|maxDepth)"],"priority":80} |
Audit parsers, serializers, tree walkers, deep clone/merge functions, and any recursive function that processes user-controlled data structures with unbounded nesting depth.
| Crash Type | Severity | Catchable? | Process Dies? |
|---|---|---|---|
| OOM (heap exhaustion) | HIGH 7.5 | NO | YES -- uncatchable, process killed |
| RangeError (stack overflow) | MEDIUM 5.3-6.5 | YES (try/catch) | Only if uncaught |
OOM crash = process dies regardless of error handling. This is HIGH severity. RangeError = catchable in try/catch. Only HIGH if the library does NOT catch it.
grep -rn "function.*recurse\|function.*recursive\|function.*walk\|function.*traverse" .
grep -rn "function.*serialize\|function.*stringify\|function.*clone\|function.*deep" .
grep -rn "function.*parse\|function.*process\|function.*visit\|function.*transform" .
Look for functions that call themselves:
# Find function definitions and then check if they self-reference
grep -rn "function\s\+\w\+" . --include="*.js" | head -50
# Then for each function name, check if it calls itself
grep -rn "maxDepth\|max_depth\|depthLimit\|depth_limit\|MAX_DEPTH" .
grep -rn "depth\s*>\|depth\s*>=\|depth\s*<\|depth\s*<=" .
grep -rn "recursion.*limit\|stack.*limit\|nesting.*limit" .
Create deeply nested input matching the data format:
// JSON-like nesting
let nested = "x";
for (let i = 0; i < 100000; i++) {
nested = { a: nested };
}
// String-based nesting
let nested = "a";
for (let i = 0; i < 100000; i++) {
nested = "[" + nested + "]";
}
// Run in subprocess to avoid crashing main process
const { execSync } = require('child_process');
try {
execSync('node -e "const pkg = require('./'); pkg.parse(payload)"', {
timeout: 10000,
maxBuffer: 1024
});
} catch (e) {
if (e.status === null) {
console.log('[+] OOM: process killed (HIGH severity)');
} else {
console.log('[!] RangeError: catchable (MEDIUM severity)');
}
}
function parse(node) {
if (node.children) {
return node.children.map(child => parse(child)); // No depth limit
}
return node.value;
}
function serialize(obj) {
if (typeof obj === 'object' && obj !== null) {
return '{' + Object.keys(obj).map(k => k + ':' + serialize(obj[k])).join(',') + '}';
}
return String(obj);
}
function deepClone(obj) {
if (typeof obj !== 'object' || obj === null) return obj;
const clone = Array.isArray(obj) ? [] : {};
for (const key in obj) {
clone[key] = deepClone(obj[key]); // Unbounded recursion
}
return clone;
}
Some recursive functions do not detect circular references:
const a = {}; a.self = a;
deepClone(a); // Infinite recursion -> stack overflow