T09 · Insecure Skill Coding Practices
- Location
reference/scripts/run_actor.js:56- Finding
Output Path Validation Permits Arbitrary File Overwrite Through Symbolic Links
- Content
View full analysis
0) { // ... writeFileSync(outputPath, csvLines.join('\n')); } else { writeFileSync(outputPath, ''); } } ``` ### Technical Analysis The validation uses `resolve()` and a string-prefix comparison to determine whether the supplied path is under the current working directory. This only performs lexical path normalization. It does not resolve symbolic links or verify the identity of the final filesystem object. Consequently, a path such as `./result.json` passes validation even when `result.json` is a symbolic link whose target is outside the working directory. Node.js `writeFileSync()` follows symbolic links by default and truncates the linked target before writing the downloaded Actor dataset. This behavior contradicts the security statement in `SKILL.md` that outputs are written only under the current working directory. Exploitation requires an attacker, another local process, or a prior operation to create or replace a writable output path with a symbolic link. ### Attack Path 1. The attacker gains the ability to create a symbolic link in the directory from ...[truncated 1650 chars]- Remediation
View remediation
