arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

怪异机器合成器:在表达式层利用AI编排

Weird Machine Compositors: Exploiting AI Orchestration at the Expression Layer

Eilon Cohen, Ariel Fogel

arXiv 2609.33413首次发表:更新:

发表机构

Pillar Security(Pillar Security)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究揭示编排平台表达式沙箱的“怪异机器”本质,通过n8n的CVE绕过证明枚举阻断不可修复,并提出AST覆盖分析工具与策略反转等防御方案。

AI 中文摘要

编排平台通过枚举和阻断沙箱机制来保护用户提供的表达式,这些机制包括:抽象语法树重写、运行时属性阻断列表、模板沙箱环境。我们证明这些沙箱是怪异机器,其指令集是底层语言规范,并且枚举和阻断方法无法修复,这遵循了导致过去沙箱技术(如Java的SecurityManager和vm2)被弃用的相同轨迹。我们通过三轮针对n8n表达式沙箱的升级绕过攻击验证了这一论断(三个CVE,两个CVSS 9.4,一个未认证),并将这些发现置于编排产品类别中沙箱失败的更广泛模式中。我们识别出一种信任洗白模式,其中编排管道和应用程序通过在各层级剥离污点的转换,将攻击者控制的输入从不信任状态移至完全凭证化状态。AI辅助枚举加速了这些覆盖漏洞的发现,压缩了沙箱部署与其被攻破之间的时间线。我们提供了一种AST覆盖分析方法、一个配套的开源工具,以及一个防御手册,其中包括策略反转(允许列表优于阻断列表)作为结构性缓解措施。

英文摘要

Orchestration platforms secure user-provided expressions through enumerate and block sandboxing: AST rewriting, runtime property blocklists, template sandbox environments. We demonstrate that these sandboxes are weird machines whose instruction set is the underlying language specification, and that the enumerate and block approach is unfixable, following the same trajectory that led to the deprecation of past sandboxing technologies such as Java's SecurityManager and vm2. We validate this claim through three rounds of escalating bypasses against n8n's expression sandbox (three CVEs, two CVSS 9.4, one unauthenticated), and frame these findings within a broader pattern of sandbox failures across the orchestration products category. We identify a trust laundering pattern where orchestration pipelines and applications move attacker controlled input from untrusted to fully credentialed through transformations that strip taint at each level. AI-assisted enumeration accelerates the discovery of these coverage gaps, compressing the timeline between a sandbox's deployment and its compromise. We provide an AST coverage analysis methodology, an accompanying open-source tool, and a defensive playbook that includes policy inversion (allowlist over blocklist) as a structural mitigation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑