Skip to content

🛡️ Sentinel: [CRITICAL/HIGH] Fix Remote Code Execution in PDF compilation#222

Open
anchapin wants to merge 1 commit intomainfrom
sentinel/fix-pdf-rce-1606002574241256488
Open

🛡️ Sentinel: [CRITICAL/HIGH] Fix Remote Code Execution in PDF compilation#222
anchapin wants to merge 1 commit intomainfrom
sentinel/fix-pdf-rce-1606002574241256488

Conversation

@anchapin
Copy link
Copy Markdown
Owner

@anchapin anchapin commented Mar 31, 2026

🚨 Severity: CRITICAL
💡 Vulnerability: Subprocess pdflatex and pandoc executed without -no-shell-escape flag and missing timeout.
🎯 Impact: Malicious inputs in Cover Letters or templates could execute arbitrary shell code via LaTeX \write18 capabilities or cause Denial of Service by infinitely compiling.
🔧 Fix: Add -no-shell-escape flag and process timeouts to PDF compilation logic in CoverLetterGenerator._compile_pdf.
✅ Verification: Ran test suite locally using python -m pytest tests/test_cover_letter_generator.py and validated passing tests. Included updated Sentinel Journal entry.


PR created automatically by Jules for task 1606002574241256488 started by @anchapin

Summary by Sourcery

Harden PDF compilation for cover letters against remote code execution and runaway LaTeX processes.

Bug Fixes:

  • Prevent LaTeX-based remote code execution by disabling shell escape for pdflatex and pandoc-driven PDF generation.
  • Mitigate denial-of-service risk from hung or infinitely compiling LaTeX processes by enforcing timeouts on PDF compilation subprocesses.

Documentation:

  • Add a Sentinel security journal entry documenting the LaTeX PDF compilation RCE and DoS vulnerability and its mitigation.

…tion

Co-authored-by: anchapin <6326294+anchapin@users.noreply.github.com>
@google-labs-jules
Copy link
Copy Markdown
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@sourcery-ai
Copy link
Copy Markdown

sourcery-ai bot commented Mar 31, 2026

Reviewer's Guide

Adds defense-in-depth against LaTeX-based RCE/DoS in cover letter PDF generation by disabling shell escapes for pdflatex/pandoc and enforcing compilation timeouts, and records the change in the Sentinel security journal.

Sequence diagram for updated PDF compilation with secure subprocess handling

sequenceDiagram
    actor User
    participant CLI as CoverLetterGenerator
    participant Pdflatex as PdflatexProcess
    participant Pandoc as PandocProcess

    User->>CLI: generate_cover_letter_pdf
    CLI->>CLI: _compile_pdf(output_path, tex_content)

    CLI->>Pdflatex: Popen([pdflatex, -interaction=nonstopmode, -no-shell-escape, tex_path])
    CLI->>Pdflatex: communicate(timeout=30)
    alt Pdflatex completes in time
        Pdflatex-->>CLI: stdout, stderr, returncode
        alt Pdflatex success or output_path exists
            CLI->>CLI: pdf_created = True
            CLI-->>User: success
        else Pdflatex failure
            CLI->>Pandoc: Popen([pandoc, tex_path, -o, output_path, --pdf-engine=xelatex, --pdf-engine-opt=-no-shell-escape])
            CLI->>Pandoc: communicate(timeout=30)
            alt Pandoc completes in time
                Pandoc-->>CLI: stdout, stderr, returncode
                alt Pandoc success or output_path exists
                    CLI->>CLI: pdf_created = True
                    CLI-->>User: success
                else Pandoc failure
                    CLI-->>User: failure
                end
            else Pandoc timeout
                CLI->>Pandoc: kill()
                Pandoc-->>CLI: stdout, stderr
                CLI-->>User: failure
            end
        end
    else Pdflatex timeout
        CLI->>Pdflatex: kill()
        Pdflatex-->>CLI: stdout, stderr
        CLI->>Pandoc: Popen([pandoc, tex_path, -o, output_path, --pdf-engine=xelatex, --pdf-engine-opt=-no-shell-escape])
        CLI->>Pandoc: communicate(timeout=30)
        alt Pandoc completes in time
            Pandoc-->>CLI: stdout, stderr, returncode
            alt Pandoc success or output_path exists
                CLI->>CLI: pdf_created = True
                CLI-->>User: success
            else Pandoc failure
                CLI-->>User: failure
            end
        else Pandoc timeout
            CLI->>Pandoc: kill()
            Pandoc-->>CLI: stdout, stderr
            CLI-->>User: failure
        end
    end
Loading

File-Level Changes

Change Details Files
Harden LaTeX PDF compilation by disabling shell escape and enforcing timeouts for pdflatex and pandoc subprocesses.
  • Add -no-shell-escape flag to the pdflatex invocation used for primary PDF compilation.
  • Wrap pdflatex communicate() in a 30-second timeout, killing the process and failing gracefully on TimeoutExpired.
  • Extend the pandoc PDF generation fallback to pass --pdf-engine-opt=-no-shell-escape to xelatex.
  • Apply the same 30-second subprocess timeout and kill-on-timeout behavior to the pandoc-based compilation path.
cli/generators/cover_letter_generator.py
Document the new RCE/DoS mitigation in the Sentinel security journal.
  • Append a new Sentinel entry describing the prior lack of -no-shell-escape and process timeouts.
  • Capture learnings about LaTeX \write18-based code execution and infinite compilation DoS.
  • Record prevention guidance requiring -no-shell-escape and communicate(timeout=X) with TimeoutExpired handling for all PDF compilation tools.
.jules/sentinel.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link
Copy Markdown

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

  • The 30-second timeout value is currently hardcoded in two places; consider extracting this into a single constant or configuration option so it’s easier to tune or adjust per environment.
  • The subprocess invocation and timeout-handling logic for pdflatex and pandoc is nearly identical; you could factor this into a small helper function to reduce duplication and keep the error-handling behavior consistent.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- The 30-second timeout value is currently hardcoded in two places; consider extracting this into a single constant or configuration option so it’s easier to tune or adjust per environment.
- The subprocess invocation and timeout-handling logic for `pdflatex` and `pandoc` is nearly identical; you could factor this into a small helper function to reduce duplication and keep the error-handling behavior consistent.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant