T09 · Insecure Skill Coding Practices
- Location
index.js:32- Finding
Unvalidated date input enables cache path traversal
- Content
View full analysis
"2026-01-27" const currentYear = getCST().getFullYear(); const shortDateMatch = dateStr.match(/^(\d{1,2})[.-](\d{1,2})$/); if (shortDateMatch) { const month = shortDateMatch[1].padStart(2, '0'); const day = shortDateMatch[2].padStart(2, '0'); dateStr = `${currentYear}-${month}-${day}`; console.log(`Auto-completed date input "${argv.date}" to: ${dateStr}`); } const dateInt = parseInt(dateStr.replace(/-/g, ''), 10); ``` ### Technical Analysis The `--date` command-line value is incorporated directly into a filename passed to `path.join()`. Only short dates matching the optional shorthand expression are normalized. All other strings, including strings containing `/`, `\`, and `..` path components, remain unchanged. The fixed `holiday_` prefix does not prevent traversal when a supplied value contains an initial ordinary component followed by parent-directory components, such as `x/../../../target`. After path normalization, the resulting path may escape `CACHE_DIR`. The read operation is attempted immediately when the derived file exists. The parsed data is subsequently treated as holiday API data. The write operation is conditional on the ...[truncated 1681 chars]- Remediation
View remediation
