T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_xhs.py:76- Finding
Unchecked Output Name Allows Directory Traversal and File Overwrite
- Content
View full analysis
3 else 5 outdir = os.path.join(os.path.dirname(__file__), "..", "账号数据", outname) os.makedirs(os.path.join(outdir, "covers"), exist_ok=True) info = api_get("get_user_info", user_id=user_id).get("data", {}) raw = fetch_all_notes(user_id, max_pages) slimmed = [slim(n) for n in raw] slimmed.sort(key=lambda x: x["likes"] + x["collected"], reverse=True) json.dump({"user_info": info, "notes": slimmed}, open(os.path.join(outdir, "notes.json"), "w"), ensure_ascii=False, indent=2) ``` ```python open(os.path.join(outdir, "summary.md"), "w").write("\n".join(lines) + "\n") ``` ```python open(os.path.join(outdir, "covers", f"{i:02d}{ext}"), "wb").write(data) ``` ### Technical Analysis The second command-line argument is incorporated directly into an output path without validation or canonical containment checks. Python path joining does not guarantee that the result remains beneath the intended `账号数据` directory: - An absolute `outname` replaces the preceding path components. - An `outname` containing `../` can traverse to parent directories. - Existing symbolic links in the selected output tree can redirect writes elsewhere. The script then opens `notes.json`, `summary.md`, and numbered cover files in write mode. Existing files with those names are truncated and overwritten. The vulnerability does not permit unrestricted filename selection, because the final filenames are fixed by the script. It does, however, permit selection of the containing directory and consequently overwrite of those fixed filenames anywhere writable by the invoking account. ### Attack Path 1. An attacker influences the value supplied as the output-directory argument. 2. The attacker suppl ...[truncated 996 chars]- Remediation
View remediation
