T09 · Insecure Skill Coding Practices
- Location
scripts/batch_render.jsx:8- Finding
Path Traversal Through Unsanitized Composition Names
- Content
View full analysis
- Remediation
View remediation
|\x00-\x1F]/g, "_"); safe = safe.replace(/\.\./g, "_"); if (safe === "" || safe === "." || safe === "..") { throw new Error("Invalid composition name for output"); } return safe; } var safeName = safeOutputName(compName); var outputDirectory = new Folder(outputPath); var destination = new File(outputDirectory.fsName + "/" + safeName + ".mov"); output.file = destination; ``` Because simple replacement alone may not cover every platform-specific path behavior, the implementation should additionally compare canonical paths and enforce that the final destination is contained within the approved output directory. ]]>
