agentsclimarketplace

Run2 jackson inject bypass

Skill cxcscmu/SkillLearnBench/skills/b2-self-feedback-claude-sonnet-4-6/fix-security-bug/run2_jackson-inject-bypass

Security guide for Jackson @JacksonInject vulnerabilities - how attackers override injectable values via JSON and how to prevent itFrom its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run2_jackson-inject-bypass

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

2.8 KB, 610 tokens by cl100k_base, as published. Nobody here has run it

Jackson @JacksonInject Security Bypass - Complete Reference

What is @JacksonInject?

@JacksonInject marks a Java constructor parameter or field to receive its value from the ObjectMapper's InjectableValues rather than from the deserialized JSON. This is used in frameworks like Apache Druid to inject server-side configuration that should not be controllable by external JSON input (e.g., druid.javascript.enabled from server properties).

The Vulnerability Pattern

@JsonCreator
public SomeFilter(
    @JsonProperty("function") String function,
    @JacksonInject SomeConfig config  // VULNERABLE
)

When useInput is OptBoolean.DEFAULT (the default), Jackson:

  • For @JsonCreator constructor params: Uses JSON input if available, falls back to injectable
  • The JSON key used to match is the injection ID (empty string "" if no ID specified)
  • An attacker can include "": {"enabled": true} in JSON to create a new SomeConfig object

OptBoolean Values Reference

ValueBehaviorSecurity
OptBoolean.DEFAULTContext-dependent; @JsonCreator params prefer JSONVULNERABLE
OptBoolean.TRUEAlways prefers JSON input over injectableVULNERABLE
OptBoolean.FALSENever reads from JSON; always uses injectableSECURE

The Fix

import com.fasterxml.jackson.annotation.OptBoolean;

// SECURE: JSON can never override the server-injected config
@JacksonInject(useInput = OptBoolean.FALSE) SomeConfig config

How to Identify Vulnerable Code

Search for: @JacksonInject in constructor parameters for security-sensitive types.

Signs of vulnerability:

  1. The injected type controls security behavior (enabled/disabled flags, permissions)
  2. No explicit useInput = OptBoolean.FALSE
  3. JSON deserialization accepts user-controlled input (REST API endpoints)

Injection ID Mechanics

When no value is specified in @JacksonInject, Jackson uses either:

  • The fully-qualified class name as the injection ID, OR
  • The empty string "" as a fallback injection ID for certain Jackson versions

The exploit uses "" as the property name in JSON to supply the "injected" value:

{ "": { "enabled": true } }

Testing the Fix

A correctly patched endpoint should return a 500 error with "JavaScript is disabled" when receiving the exploit payload, even if "": {"enabled": true} is present.

Other Vulnerable Patterns to Audit

Any use of @JacksonInject in:

  • @JsonCreator-annotated constructors that accept user-controlled JSON
  • REST API request/response DTOs
  • Jackson polymorphic type handling with @JsonTypeInfo

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.