Severity: P2 (latent atom-table DoS) · Tier-1 (mechanical)
Co-maintained repo (Pascal = architect).
Location: packages/live_ui/lib/live_ui/runtime/browser_bridge.ex:89-95
normalize_key/1 does String.to_existing_atom(binary) with a rescue ArgumentError -> String.to_atom(binary) fallback over EVERY key of an incoming hook payload (normalize_map/1), before take_keys/2 filters to the allowlist. Mitigated today (module is a placeholder, authoritative?() == false, not wired to a concrete channel handle_in), so latent — but a DoS vector once the bridge goes authoritative.
Fix: drop the String.to_atom fallback — discard keys not in the allowlist rather than interning them.
2026-05-28 cross-repo review — see ariston-ui docs/audits/cross-repo-review-2026-05-28.md (finding C5).
Severity: P2 (latent atom-table DoS) · Tier-1 (mechanical)
Co-maintained repo (Pascal = architect).
Location:
packages/live_ui/lib/live_ui/runtime/browser_bridge.ex:89-95normalize_key/1doesString.to_existing_atom(binary)with arescue ArgumentError -> String.to_atom(binary)fallback over EVERY key of an incoming hook payload (normalize_map/1), beforetake_keys/2filters to the allowlist. Mitigated today (module is a placeholder,authoritative?() == false, not wired to a concrete channelhandle_in), so latent — but a DoS vector once the bridge goes authoritative.Fix: drop the
String.to_atomfallback — discard keys not in the allowlist rather than interning them.2026-05-28 cross-repo review — see ariston-ui
docs/audits/cross-repo-review-2026-05-28.md(finding C5).