Executive brief
The SourceCodester Customer Review App is a Python-based desktop application used to collect and store user feedback. A vulnerability in the way it handles user input allows a local user to crash the application or cause permanent data loss. By submitting excessively large or malformed review data, an attacker can bloat the storage file until the app becomes unresponsive or corrupt the database so that all existing reviews are deleted.
Technical details
The vulnerability exists in the review_app.py file within the add_review, save_review, and get_all_reviews functions. The application fails to validate the length of user-supplied strings in the 'name' and 'comment' fields before writing them to the local reviews.json file. A local attacker can exploit this by submitting massive amounts of data, leading to disk bloat and application hangs (DoS). Additionally, the application uses a bare 'except' clause when reading the JSON database; if an attacker manually corrupts the JSON file structure, the application silently fails and returns an empty list, resulting in the loss of all stored review data. Public exploit code is available.
Affected products
- SourceCodester Customer Review App 1.0
Timeline
- 2026-05-12: disclosed: Initial PoC published on Pastebin
- 2026-06-01: advisory: CVE published and NVD record created