一键导入
recursion-dos
Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Generate polished, human-sounding vulnerability disclosure reports for GHSA, HackerOne, and email. Auto-selects channel, calculates CVSS, and adapts tone.
Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
Detect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.
Cross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.
| name | recursion-dos |
| description | Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits. |
| metadata | {"filePattern":["**/*.js","**/*.ts","**/*.py","**/*.go"],"bashPattern":["grep.*(recursive|recurse|depth|maxDepth)"],"priority":80} |
Audit parsers, serializers, tree walkers, deep clone/merge functions, and any recursive function that processes user-controlled data structures with unbounded nesting depth.
| Crash Type | Severity | Catchable? | Process Dies? |
|---|---|---|---|
| OOM (heap exhaustion) | HIGH 7.5 | NO | YES -- uncatchable, process killed |
| RangeError (stack overflow) | MEDIUM 5.3-6.5 | YES (try/catch) | Only if uncaught |
OOM crash = process dies regardless of error handling. This is HIGH severity. RangeError = catchable in try/catch. Only HIGH if the library does NOT catch it.
grep -rn "function.*recurse\|function.*recursive\|function.*walk\|function.*traverse" .
grep -rn "function.*serialize\|function.*stringify\|function.*clone\|function.*deep" .
grep -rn "function.*parse\|function.*process\|function.*visit\|function.*transform" .
Look for functions that call themselves:
# Find function definitions and then check if they self-reference
grep -rn "function\s\+\w\+" . --include="*.js" | head -50
# Then for each function name, check if it calls itself
grep -rn "maxDepth\|max_depth\|depthLimit\|depth_limit\|MAX_DEPTH" .
grep -rn "depth\s*>\|depth\s*>=\|depth\s*<\|depth\s*<=" .
grep -rn "recursion.*limit\|stack.*limit\|nesting.*limit" .
Create deeply nested input matching the data format:
// JSON-like nesting
let nested = "x";
for (let i = 0; i < 100000; i++) {
nested = { a: nested };
}
// String-based nesting
let nested = "a";
for (let i = 0; i < 100000; i++) {
nested = "[" + nested + "]";
}
// Run in subprocess to avoid crashing main process
const { execSync } = require('child_process');
try {
execSync('node -e "const pkg = require('./'); pkg.parse(payload)"', {
timeout: 10000,
maxBuffer: 1024
});
} catch (e) {
if (e.status === null) {
console.log('[+] OOM: process killed (HIGH severity)');
} else {
console.log('[!] RangeError: catchable (MEDIUM severity)');
}
}
function parse(node) {
if (node.children) {
return node.children.map(child => parse(child)); // No depth limit
}
return node.value;
}
function serialize(obj) {
if (typeof obj === 'object' && obj !== null) {
return '{' + Object.keys(obj).map(k => k + ':' + serialize(obj[k])).join(',') + '}';
}
return String(obj);
}
function deepClone(obj) {
if (typeof obj !== 'object' || obj === null) return obj;
const clone = Array.isArray(obj) ? [] : {};
for (const key in obj) {
clone[key] = deepClone(obj[key]); // Unbounded recursion
}
return clone;
}
Some recursive functions do not detect circular references:
const a = {}; a.self = a;
deepClone(a); // Infinite recursion -> stack overflow