T09 · Insecure Skill Coding Practices
- Location
index.js:205- Finding
Path Traversal Through Unsanitized Stock Name
- Content
View full analysis
`- ${r}`).join('\n')} --- *报告由 China Stock Sentiment 技能生成* `; fs.writeFileSync(outputPath, markdown, 'utf8'); console.log(`报告已保存至:${outputPath}`); } ``` ```js } else if (command === 'report' && args[1]) { const stockName = args[1]; // 模拟新闻数据 const mockNews = [ { title: `${stockName}业绩超预期,净利润增长 50%`, content: '公司发布财报...' }, { title: `${stockName}获得大额订单`, content: '与某知名企业签订合作协议...' }, { title: `分析师看好${stockName}后市表现`, content: '多家券商给出买入评级...' } ]; const report = generateReport(stockName, mockNews); const outputPath = path.join(process.cwd(), 'memory', 'stock-sentiment', 'reports', `${stockName}-${Date.now()}.md`); saveReport(report, outputPath); ``` ### Technical Analysis The CLI accepts `stockName` directly from `process.argv` and embeds it into the report filename without validation. An attacker can include directory traversal components such as `../` in this value. Although `path.join()` constructs the path, it also normalizes traversal components. It does not verify that the normalized destination remains under the intended `memory/stock-sentiment/reports` directory. The resulting path is passed to `saveReport()`, which recursively creates its ...[truncated 2041 chars]- Remediation
View remediation
