T09 · Insecure Skill Coding Practices
- Location
simple_api.py:214- Finding
Caller-Controlled Output Path Allows Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Path: base = output_dir.resolve() supplied = Path(filename) if supplied.is_absolute() or supplied.name != filename: raise ValueError("Output must be a plain filename") if supplied.suffix.lower() != extension: raise ValueError(f"Output filename must end with {extension}") candidate = (base / supplied.name).resolve() if candidate.parent != base: raise ValueError("Output path escapes the configured output directory") if candidate.exists(): raise FileExistsError(f"Output file already exists: {candidate}") return candidate ``` Use this helper before every save operation: ```python output_path = _safe_output_path( self.output_dir, output_filename, ".xlsx", ) wb.save(str(output_path)) ``` If nested output directories are an intended feature, use `candidate.relative_to(base)` after resolution instead of requiring `candidate.parent == base`, and reject the path when `relative_to()` raises `ValueError`. ]]>
