T09 · Insecure Skill Coding Practices
- Location
scripts/omoc.py:111- Finding
Path Traversal in Team Mailbox File Operations
- Content
View full analysis
/mailbox/` directory. An absolute path is also dangerous because joining a `pathlib.Path` with a subsequent absolute path discards the preceding mailbox path. The implementation automatically appends `.json`, which limits targets to paths ending in that extension but does not prevent traversal. The mailbox read operation parses and prints any accessible valid JSON file. The send ...[truncated 2349 chars]- Remediation
View remediation
Path: safe(worker, 'worker') return td(team) / 'mailbox' / f'{worker}.json' ``` 2. Require mailbox participants to belong to the configured team roster: ```python def require_worker(team: str, worker: str) -> None: workers = {item['name'] for item in cfg(team).get('workers', [])} if worker not in workers: raise SystemExit(f'worker_not_found: {worker}') ``` Apply this check to recipients and mailbox readers. If leaders are valid mailbox participants, represent and validate them explicitly rather than accepting arbitrary names. 3. Enforce resolved-path containment as defense in depth: ```python def mailbox_path(team: str, worker: str) -> Path: safe(worker, 'worker') base = (td(team) / 'mailbox').resolve() target = (base / f'{worker}.json').resolve() if target.parent != base: raise SystemExit('invalid mailbox path') return target ``` 4. Explicitly reject absolute paths, path separators, `.` components, and `..` components before accessing the filesystem. 5. Use the centralized safe path function for both reads and writes so future mailbox commands cannot omit validation. 6. Validate the decoded mailbox schema before modifying it. Confirm that the root value is an object and that `messages` is a list of bounded, expected message objects. 7. Add regression tests covering: - Relative traversal sequences. - Absolute paths. - Nested path separators. - Unknown workers. - Valid configured workers. - Symlink-based containment escapes. - Malformed and schema-incompatible JSON targets. ]]>
