T09 · Insecure Skill Coding Practices
- Location
scripts/integrity.py:625- Finding
Workspace Boundary Traversal in File Acceptance and Snapshot Restoration
- Content
View full analysis
Path | None: """Get the snapshot path for a file, or None if no snapshot exists.""" p = snapshot_dir(workspace) / rel return p if p.is_file() else None ``` ### Technical Analysis The user-provided file path is only normalized by replacing backslashes with forward slashes. The implementation does not reject absolute paths, `..` components, symlinks, or resolved paths outside the configured workspace. In `cmd_accept`, joining an absolute path to `workspace` can discard the workspace prefix under `pathlib` semantics. A path containing traversal components can similarly resolve outside the workspace. The command can therefore hash and register arbitrary readable files rather than only files belonging to the monitored workspace. The rest ...[truncated 2276 chars]- Remediation
View remediation
