AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

Merge pull request #10874 from spesmilo/plugin_zipfile

Public commit record

What the developer wrote

Authored by Felix

78/100 · Adequate
Merge pull request #10874 from spesmilo/plugin_zipfile

plugins: load zip plugins from the bytes whose signature was verified
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit hardens how Electrum loads third-party plugins. Previously, the app could authorize a plugin zip file, then later re-read that same file from disk to run it. An attacker who could replace the file in the brief gap (a 'time-of-check/time-of-use' or TOCTOU race) might get malicious code executed despite the signature check. The fix keeps the verified plugin bytes in memory and loads all code and icons from those bytes, so the file on disk can no longer be swapped in after approval. It also adds a plugin upgrade flow and new safety checks.

Recommended action

Treat this as a security-hardening fix and include it in the next release. Users who install third-party plugins should upgrade. Reviewers should pay special attention to MemoryZipImporter's locking, module path validation, and the hash verification paths in _read_check_bytes and _get_zip_importer. No separate CVE is evident from the commit materials.

Security signals we found

01

Fixes time-of-check/time-of-use (TOCTOU) race between plugin signature verification and disk-based module loading

02

Introduces in-memory zip importer to prevent on-disk substitution after authorization

03

Adds hash verification (sha256) before loading plugin code or reading plugin resources

04

Adds 10 MB size limit when reading plugin zip files

05

Hardens signature verification path against malformed signatures and path mismatches

06

Adds regression tests simulating malicious zip replacement and verifying rejection

07

Adds plugin upgrade flow with hash-checked byte copying

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.