T09 · Insecure Skill Coding Practices
- Location
flair/generate-flair.py:95- Finding
Arbitrary File Overwrite Through Unrestricted Output Path
- Content
View full analysis
Vulnerability Details
File Location:
flair/generate-flair.py, lines 95–97 and 108
Vulnerability Type: Arbitrary file overwrite
Risk Level: MediumVulnerable Code:
python if output_path: with open(output_path, "w", encoding="utf-8") as f: f.write(svg) return output_pathThe path originates directly from a command-line argument:
python output = sys.argv[3] if len(sys.argv) > 3 else NoneTechnical Analysis
The third command-line argument is accepted as
output_pathand passed unchanged toopen()in truncating write mode. The script does not restrict output to a designated directory, reject absolute paths or traversal components, validate the resolved path, or protect against symbolic-link targets.Consequently, a caller that controls this argument can direct the generated SVG content to any file writable by the process. The vulnerability does not independently elevate operating-system privileges; its reach is limited to the filesystem permissions of the user or Agent process running the script.
Attack Path
- An attacker influences the flair-generation output-path argument, directly or through an Agent request.
- The attacker supplies an absolute path, a traversal path such as
../../target, or a path resolving through a symbolic link. - The CLI assigns the untrusted value to
output. generate_flair()receives it asoutput_path.open(output_path, "w")creates or truncates the selected writable file.- The script replaces the target's contents with generated SVG data.
Impact Assessment
Successful exploitation permits creation or overwrite of files available to the invoking process. This can corrupt workspace data, source files, local configuration, prediction records, or Agent state. If the process has access to security-sensitive configuration or executable startup files, overwriting those files may cause broader integrity ...[truncated 120 chars]
- Remediation
View remediation
Remediation Suggestions
- Write generated files only beneath a dedicated output directory.
- Resolve both the trusted base directory and requested destination with
pathlib.Path.resolve(), then verify that the destination remains beneath the base. - Reject absolute paths,
..traversal, unexpected path separators, and invalid filename characters. - Generate server-side filenames instead of accepting arbitrary destination paths where possible.
- Reject symbolic-link destinations and inspect parent components to prevent symlink-based escapes.
- Use exclusive creation mode (
"x") when overwriting is unnecessary. - Run the generator with minimal filesystem permissions.
- Return a clear validation error for destinations outside the authorized directory.
