T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:503- Finding
Prefix-Based Path Validation Allows Reads Outside the Intended Root
- Content
View full analysis
- Remediation
View remediation
str: candidate = (TRUSTED_ROOT / path).resolve() if not candidate.is_relative_to(TRUSTED_ROOT): raise ValueError("Path traversal blocked by governance") if not candidate.is_file(): raise ValueError("Requested path is not a regular file") return candidate.read_text() ``` For Python versions without `Path.is_relative_to()`, use `os.path.commonpath()` and verify that the common path equals the trusted root. Additional hardening should include: - Rejecting absolute user-supplied paths if only workspace-relative paths are required. - Running the agent under a minimally privileged operating-system account. - Restricting access to symbolic links where the deployment threat model requires it. - Defining the trusted root in immutable application configuration rather than deriving it from the current working directory. - Adding regression tests for sibling-prefix paths, `..` components, absolute paths, and symbolic-link escapes. ]]>
