Team Ai
Apppublic

Dave-13/DevSecOps

sourceHugging Faceupdated 6mo agoView on Hugging Face
0likes
buggy_app.py28 linesDownload Raw Back to examples
1import sqlite32 3 4def get_user(username: str) -> dict:5    conn = sqlite3.connect(":memory:")6    conn.execute("CREATE TABLE users (id INTEGER, username TEXT, role TEXT)")7    conn.execute("INSERT INTO users VALUES (1, 'admin', 'superuser')")8    conn.commit()9 10    # BUG 1: SQL injection vulnerability11    query = "SELECT * FROM users WHERE username = '" + username + "'"12    cursor = conn.execute(query)13    row = cursor.fetchone()14    if row:15        return {"id": row[0], "username": row[1], "role": row[2]}16    return {}17 18 19def calculate_ratio(a: int, b: int) -> float:20    # BUG 2: No zero-division guard21    return a / b22 23 24def process_input(data: str) -> str:25    # BUG 3: unsafe eval26    result = eval(data)27    return str(result)28