lov-sync-with-synology
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecurityscripts/fake_dsm_server.py
MEDIUMSecurityMEDIUM
scripts/fake_dsm_server.py
The code appears to be a fake DSM test server rather than malware. It contains a significant path traversal risk in both filesystem reads and uploads because requested paths are not normalized and checked to remain beneath the configured root. Authentication is intentionally weak and several endpoints are unauthenticated, which is acceptable only for an isolated test fixture. The hardcoded SID and token are placeholders, not evidence of credential theft. The literal fragment also appears syntactically incomplete at the final SystemExit call.
Confidence: 98%Severity: 72%
Audit Metadata