{"record":{"id":"1ff860def49870cd","repo":"Tencent/WeKnora","slug":"stdin-injection-detected","errorCode":null,"errorMessage":"stdin injection detected","messagePattern":"stdin injection detected","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/sandbox/sandbox.go","lineNumber":108,"sourceCode":"\n\t// DefaultE2BSandboxTTL matches the E2B SDK's built-in default so an\n\t// unset E2BSandboxTTL still yields a valid sandbox lifetime.\n\tDefaultE2BSandboxTTL = 5 * time.Minute\n\t// DefaultE2BHTTPTimeout bounds a single HTTP call to the E2B API.\n\tDefaultE2BHTTPTimeout = 30 * time.Second\n)\n\n// Common errors\nvar (\n\tErrSandboxDisabled   = errors.New(\"sandbox is disabled\")\n\tErrTimeout           = errors.New(\"execution timed out\")\n\tErrScriptNotFound    = errors.New(\"script not found\")\n\tErrInvalidScript     = errors.New(\"invalid script\")\n\tErrExecutionFailed   = errors.New(\"script execution failed\")\n\tErrSecurityViolation = errors.New(\"security validation failed\")\n\tErrDangerousCommand  = errors.New(\"script contains dangerous command\")\n\tErrArgInjection      = errors.New(\"argument injection detected\")\n\tErrStdinInjection    = errors.New(\"stdin injection detected\")\n)\n\n// Sandbox defines the interface for isolated script execution\ntype Sandbox interface {\n\t// Execute runs a script in an isolated environment\n\tExecute(ctx context.Context, config *ExecuteConfig) (*ExecuteResult, error)\n\n\t// Cleanup releases sandbox resources\n\tCleanup(ctx context.Context) error\n\n\t// Type returns the sandbox type\n\tType() SandboxType\n\n\t// IsAvailable checks if the sandbox is available for use\n\tIsAvailable(ctx context.Context) bool\n}\n\n// Manager provides a unified interface for sandbox operations","sourceCodeStart":90,"sourceCodeEnd":126,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/sandbox/sandbox.go#L90-L126","documentation":"Sentinel error ErrStdinInjection returned by the sandbox manager when a script execution result reports that the sandbox detected stdin injection — i.e. the executed script attempted to feed unsanitized input into a command's stdin, which is treated as a security violation. It fires whenever the execution result's Errors contain an injection report; it is a deliberate rejection, not an infrastructure failure.","triggerScenarios":"Thrown at internal/sandbox/sandbox.go:108 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Reject the request and surface the error to the caller without retrying, since the script content itself violates the stdin policy","Sanitize or remove stdin redirection/piping of untrusted input in the submitted script before resubmitting","Log the offending script and tenant/session identifiers for security audit","If the injection flag is a false positive, adjust the script to read arguments or files instead of stdin"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}