T09 · Insecure Skill Coding Practices
- Location
scripts/chown.py:5- Finding
Unvalidated ownership change follows symbolic links
- Content
View full analysis
Vulnerability Details
File Location:
scripts/chown.py, lines 5-12
Vulnerability Type: Unrestricted filesystem ownership change with symbolic-link following
Risk Level: MediumVulnerable Code:
python parser.add_argument('owner') parser.add_argument('file') args = parser.parse_args() try: import pwd, grp u, g = args.owner.split(':') if ':' in args.owner else (args.owner, None) uid = pwd.getpwnam(u).pw_uid gid = grp.getgrnam(g).gr_gid if g else -1 os.chown(args.file, uid, gid)Technical Analysis
The tool accepts an arbitrary filesystem path and passes it directly to
os.chown. No allowed-root validation, canonical-path verification, file-type check, or symbolic-link restriction is applied.Python's
os.chownfollows symbolic links by default. If the tool is executed with elevated privileges and an attacker can supply, create, or replace the target path, a symbolic link can redirect the ownership change to a different file. A path replacement between validation and use would also create a time-of-check/time-of-use risk if path validation were added without using safer descriptor-based operations.The vulnerability is conditional on the process having sufficient privileges to change ownership and the attacker being able to influence the supplied path or its filesystem components.
Attack Path
- A privileged user or service invokes this utility using a path influenced by a less-privileged attacker.
- The attacker creates or replaces that path with a symbolic link to a protected file.
- The attacker selects an account that should receive ownership, where control over the
ownerargument is available. - The utility resolves the requested account and invokes
os.chownon the attacker-controlled path. os.chownfollows the symbolic link and changes the ownership of the protected target.- Depending on the target's permissions and system policy, t ...[truncated 671 chars]
- Remediation
View remediation
Remediation Suggestions
- Run the utility with the least privileges required and avoid exposing it through unrestricted
sudo, setuid wrappers, or privileged services. - Restrict targets to explicitly approved directories and reject paths outside those roots.
- Resolve and verify path components while accounting for symbolic links and filesystem race conditions.
- If the link itself should be modified, use
os.lchown()oros.chown(..., follow_symlinks=False). - If symbolic links are not required, explicitly reject them and use descriptor-based operations where supported to reduce path-replacement races.
- Restrict which destination users and groups may be selected rather than accepting arbitrary account names in privileged contexts.
- Log the canonical target, requested ownership, invoking identity, and operation result for privileged use.
- Run the utility with the least privileges required and avoid exposing it through unrestricted
