Finding
discoverLeafComponents recurses into directories without checking whether entries are symbolic links. A directory tree containing a symlink cycle causes infinite recursion and a stack overflow.
Location
src/analysis/discoverLeafComponents.ts — the recursive walker calls itself on dirent.isDirectory() but has no dirent.isSymbolicLink() guard or depth limit.
Impact
- A project with a symlink loop (e.g.
node_modules/.bin on some platforms, or a manually crafted fixture) causes the process to crash.
- Reachable through
autogen-markdown-doc's orchestration layer.
Fix
Add a symlink guard before recursing:
if (dirent.isSymbolicLink()) continue;
Optionally also add a maxDepth parameter defaulting to a safe value (e.g. 20).
Severity
🟠 Security / correctness (potential DoS via crafted input)
Finding
discoverLeafComponentsrecurses into directories without checking whether entries are symbolic links. A directory tree containing a symlink cycle causes infinite recursion and a stack overflow.Location
src/analysis/discoverLeafComponents.ts— the recursive walker calls itself ondirent.isDirectory()but has nodirent.isSymbolicLink()guard or depth limit.Impact
node_modules/.binon some platforms, or a manually crafted fixture) causes the process to crash.autogen-markdown-doc's orchestration layer.Fix
Add a symlink guard before recursing:
Optionally also add a
maxDepthparameter defaulting to a safe value (e.g. 20).Severity
🟠 Security / correctness (potential DoS via crafted input)