agentsclimarketplace

Jackson inject security

Skill cxcscmu/SkillLearnBench/skills/b1-one-shot-claude-opus-4-6/fix-security-bug/jackson-inject-security

[COLM'26] SkillLearnBench is the first benchmark for evaluating continual learning methods that automatically generate agent skills.

Install
npx -y skills add cxcscmu/SkillLearnBench --skill jackson-inject-security

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Preventing Jackson @JacksonInject override attacks where JSON input can replace server-side injected values.

SKILL.md

1.7 KB, 348 tokens by cl100k_base, as published. Nobody here has run it

Jackson @JacksonInject Security

The Vulnerability

When using @JacksonInject in Jackson @JsonCreator constructors, JSON input can override server-side injected values by default. This happens because @JacksonInject defaults to useInput = OptBoolean.DEFAULT, which allows JSON properties to take precedence over injected values.

Attack Mechanism

If a class has:

@JsonCreator
public MyClass(@JacksonInject MyConfig config) { ... }

An attacker can send JSON with "": {"enabled": true} to override the injected config value. The empty string key "" maps to inject parameters that have no explicit ID.

Combined with FAIL_ON_UNKNOWN_PROPERTIES = false (common in many frameworks), the attack payload passes silently.

Fix: useInput = OptBoolean.FALSE

Jackson 2.9+ introduced OptBoolean for @JacksonInject:

import com.fasterxml.jackson.annotation.OptBoolean;

@JsonCreator
public MyClass(
    @JacksonInject(useInput = OptBoolean.FALSE) MyConfig config
) { ... }

This prevents JSON input from overriding the injected value entirely.

Additional Defense: Constructor Validation

Add validation in the constructor to check the config before storing it:

@JsonCreator
public MyClass(
    @JacksonInject(useInput = OptBoolean.FALSE) MyConfig config
) {
    Preconditions.checkState(config.isEnabled(), "Feature is disabled");
    this.config = config;
}

Jackson Version Compatibility

  • OptBoolean.FALSE for @JacksonInject(useInput=...) requires Jackson 2.9+
  • Check with: <jackson.version> in pom.xml

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.