retail-virtual-tryon
Audited by Socket on Sep 21, 2026
2 alerts found:
SecurityAnomalyThe code appears to implement legitimate virtual try-on functionality and contains no clear malware or intentional sabotage. However, it exposes powerful unauthenticated file and cloud-object access primitives: arbitrary gs:// reads, broad local path handling, arbitrary catalog scanning, and publicly mounted cache content. Wildcard CORS with credentials and missing request-size limits further increase exposure. Restrict paths and buckets, add authentication and authorization, sanitize filenames, validate media and request sizes, avoid exposing .catalog_cache, and return generic error messages.
The code is a straightforward Google Cloud Run deployment script with no evident malware or supply-chain backdoor. It performs privileged cloud changes and uploads the entire current directory. The explicit `--allow-unauthenticated` flag creates a significant exposure risk if public access is not intended, and the source directory should be checked for secrets before deployment.