T09 · Insecure Skill Coding Practices
- Location
scripts/read.sh:85- Finding
Insufficient validation of WebDAV ZIP archives before extraction
- Content
View full analysis
/dev/null | grep -qE '(^|/)\.\.(/|$)|^/'; then echo "Error: zip archive contains unsafe path entries; refusing to extract." >&2 exit 1 fi unzip -q "$LOCAL_ZIP_PATH" -d "$TMP_DIR" ``` `scripts/read_universal.sh:146-150`: ```bash if unzip -Z1 "$ZIP_PATH" 2>/dev/null | grep -qE '(^|/)\.\.(/|$)|^/'; then echo "Error: zip archive contains unsafe path entries; refusing to extract." >&2 exit 1 fi unzip -q "$ZIP_PATH" -d "$TMP_DIR" ``` ### Technical Analysis Both readers download ZIP archives from the configured WebDAV server and extract them with `unzip`. The validation only examines entry names for absolute paths and explicit `..` path components. This check does not verify: - Whether entries are symbolic links or other special file types. - Whether a symbolic-link target points outside the temporary directory. - Whether later archive entries are extracted through a previously created link. - The number of archive entries. - The total uncompressed size or compression ratio. - Whether the resolved destination of every extracted file remains under `TMP_DIR`. On `unzip` implementations or configurations that restore symbolic links and subsequently follow them during extraction, a crafted archive may use link semantics to cause files to be written outside the intended temporary directory. Independently of symbolic-link behavior, an archive with a very large expanded size can exhaust local disk space because no extraction quota is enforced. The archive originates from user-configured WebDAV storage. Consequently, exploitation requires compromise or malicious control of that storage, its credentials, or the stored attachment archive. ### Attack Path 1. An attacker obtains ...[truncated 1599 chars]- Remediation
View remediation
