Phil is a user on octodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

I could use some extra eyes on some Masto code that is striking me as a security concern.

Look at dropbox.com/s/i0h8yg4z2oril0u/ which is a log snippet

From what I can see, every time masto gets a file, incl profile images and headers from federated instances, it shells out to imagemagick to resize and convert it.

Part of that is here github.com/tootsuite/mastodon/

Given imagetragick.com this seems ... bad

Phil @pja

@sungo You’re right. Imagemagick is not in any way secure.

· Web · 0 · 0