T09 · Insecure Skill Coding Practices
- Location
monitor.py:61- Finding
User-Controlled State Path Permits Arbitrary File Overwrite
- Content
View full analysis
Optional[str]: if "state_file" in req: v = req["state_file"] if v in (False, None, ""): return None return str(v).strip() env = os.environ.get("JISU_STOCK_MONITOR_STATE", "").strip() if env: return env return None ``` ```python def _save_state(path: str, state: dict) -> None: if not path: return state["version"] = STATE_VERSION d = os.path.dirname(os.path.abspath(path)) if d and not os.path.isdir(d): os.makedirs(d, exist_ok=True) fd, tmp = tempfile.mkstemp(suffix=".json", prefix="jisu-sm-", dir=d or None) try: with os.fdopen(fd, "w", encoding="utf-8") as f: json.dump(state, f, ensure_ascii=False, indent=2) os.replace(tmp, path) except Exception: try: os.unlink(tmp) except OSError: pass raise ``` ### Technical Analysis The `state_file` value is accepted directly from request JSON and converted into a filesystem path without validating its destination. The save routine converts it to an absolute parent directory, creates missing directories, and then uses `os.replace()` to replace the selected target with generated state JSON. There is no restriction requiring the destination to remain inside a dedicated application state directory. There is also no check that an existing destination is a legitimate state file. Consequently, anyone able to influence the monitor configuration can select any path writable by the operating-system account running the Skill. The temporary file itself is created securely through `tempfile.mkstemp()`. The vulnerability is not predictable temporary-file creation; it is the unrestricted final destination passed to ...[truncated 1280 chars]- Remediation
View remediation
