T09 · Insecure Skill Coding Practices
- Location
scripts/append_entry.py:56- Finding
Unrestricted File Append Through an Unvalidated Ledger Path
- Content
View full analysis
0: with open(csv_file, "rb") as f: f.seek(-1, 2) needs_newline = f.read(1) != b"\n" with open(csv_file, "a", encoding="utf-8", newline="") as f: if needs_newline: f.write("\n") f.write(csv_line) ``` ```python parser.add_argument("--csv-file", required=True, help="Path to the CSV file") ``` ```python args = parser.parse_args() row, entry_id = build_row(args) csv_line = row_to_csv_string(row) append_to_file(args.csv_file, csv_line) ``` The associated Skill workflow permits a user-supplied path when automatic discovery fails: ```markdown Use Glob to find `QianJi_*.csv` in the project root directory. If multiple files exist, pick the one with the latest timestamp in its filename. If no CSV file is found, tell the user and ask them to specify the path. ``` ### Technical Analysis The `--csv-file` argument is passed directly into `os.path.getsize()` and `open()` without validating that the target: - Has a `.csv` extension. - Is a regular file rather than a symbolic link or special file. - Resides in an approved ledger directory. - Has the expected QianJi 18-column header. - Is actually the ledger presented to the user during confirmation. The script therefore accepts any existing path writable by its operating-system user. Python follows symbolic links by default, so a path that appeared to identify a ledger could also resolve to another writable target. This is not an operating-system privilege escalati ...[truncated 1649 chars]- Remediation
View remediation
