T09 · Insecure Skill Coding Practices
- Location
scripts/main.js:100- Finding
Path Traversal Enables Writes Outside the Intended Output Directory
- Content
View full analysis
sanitizeFilename(segment)) .join('/') .replace(/^\/+/, ''); } function writeTextFile(url, contentType, text) { const localPath = urlToLocalPath(url, contentType); const filePath = path.join(outputDir, localPath); ensureDir(filePath); fs.writeFileSync(filePath, text, 'utf8'); logInfo('✔ text', localPath); } function writeBinaryFile(url, contentType, buffer) { const localPath = urlToLocalPath(url, contentType); const filePath = path.join(outputDir, localPath); ensureDir(filePath); fs.writeFileSync(filePath, buffer); logInfo('✔ bin ', localPath); } ``` ### Technical Analysis The local filename is derived from an attacker-influenced response URL. The code applies `decodeURIComponent()` to the URL pathname before converting it into a filesystem path. Encoded path separators can therefore become literal separators after URL parsing. Although each segment is passed through `sanitizeFilename()`, that function only replaces reserved characters and control characters. It does not reject the special filesystem segments `.` and `..`. Consequently, a pathname conta ...[truncated 2000 chars]- Remediation
View remediation
