T09 · Insecure Skill Coding Practices
- Location
scripts/editor.py:276- Finding
Output Path Traversal Through Unvalidated Output Name
- Content
View full analysis
- Remediation
View remediation
str: if not re.fullmatch(r"[A-Za-z0-9_-]+", output_name): raise ValueError("Invalid output name") final_dir = (Path(self.work_dir) / "final").resolve() destination = (final_dir / f"{output_name}_final.jpg").resolve() if destination.parent != final_dir: raise ValueError("Output path escapes the final directory") if destination.exists(): raise FileExistsError(f"Output already exists: {destination}") return str(destination) ``` Use this function instead of constructing the destination directly with unvalidated caller input. If callers need to select an output directory, expose that as a separate parameter and enforce an explicit directory policy. ]]>
