T09 · Insecure Skill Coding Practices
- Location
scripts/read.py:49- Finding
Predictable shared cache files expose sensitive document content and permit cross-process interference
- Content
View full analysis
Vulnerability Details
File Location:
scripts/read.py, lines 49-50, 109-111, 271-281, and 598
Vulnerability Type: Predictable temporary files and non-isolated shared workspace
Risk Level: HighVulnerable Code
python # Use a fixed temp directory to avoid repeated authorization prompts _TEMP_DIR = Path.home() / ".cache" / "redact_temp" _TEMP_DIR.mkdir(parents=True, exist_ok=True)python for idx, pred in enumerate(predictions): pred_dir = _TEMP_DIR / f"ppstructure_res_{idx}" pred_dir.mkdir(parents=True, exist_ok=True) pred.save_to_json(str(pred_dir))python def ocr_image(pipeline, image: Image.Image) -> Tuple[List[TextRegion], List[str]]: """Run OCR on a PIL Image and return text regions.""" # Save image to temp file in fixed directory tmp_path = _TEMP_DIR / "ocr_temp_image.png" image.save(tmp_path, "PNG") try: results, markdown_texts = run_pipeline(pipeline, tmp_path) regions = collect_regions(results) return [r for r in regions if r.text], markdown_texts finally: if tmp_path.exists(): tmp_path.unlink()python # Use fixed temp directory instead of creating new one pdf_path = _TEMP_DIR / f"{file_path.stem}.pdf"Technical Analysis
The reader places rendered images, OCR JSON, and converted PDFs in one persistent cache directory using predictable names. The names contain no process identifier or cryptographically random component. Every OCR operation uses
ocr_temp_image.png, every first prediction usesppstructure_res_0, and Office conversions use only the source filename stem.Consequently, concurrent invocations can overwrite, consume, or delete one another's files. The application also does not explicitly enforce restrictive permissions on
_TEMP_DIRor its files. Depending on the host's umask and cache-directory permissions, other local users may be ...[truncated 1630 chars]- Remediation
View remediation
Remediation Suggestions
- Create a private per-invocation workspace with
tempfile.TemporaryDirectory(prefix="redact-"). - Explicitly set the directory mode to
0700and generated-file modes to0600. - Generate every image, PDF, and OCR result path inside that unique workspace.
- Do not derive temporary names solely from user-controlled filename stems.
- Reject symbolic links where files are security-sensitive, or use exclusive creation primitives such as
os.open()withO_CREAT | O_EXCL | O_NOFOLLOWwhere supported. - Remove the entire workspace in a
finallyblock usingTemporaryDirectorycleanup. - Add concurrency tests that run multiple OCR and Office conversions simultaneously and verify that no files are shared.
- Create a private per-invocation workspace with
