T09 · Insecure Skill Coding Practices
- Location
scripts/build_searchable_pdf.py:98- Finding
Predictable Temporary PDF and Image Paths Permit File Overwrite and Symlink Attacks
- Content
View full analysis
` - `temp_image.pdf` It does not verify whether these paths already exist, whether they are symbolic links, or whether the output directory is writable by other users. The file-writing operations are also not performed with exclusive creation semantics. If an untrusted user can write to the selected output directory, that user can pre-create one of these predictable paths as a symbolic link to another file writable by the scanning process. When OpenCV, Pillow, or OCRmyPDF writes to the path, the linked target may be overwritten. Predictable paths also allow concurrent executions to overwrite or consume each other's intermediate files. The generated final filename is similarly not checked for collisions, so two documents producing the same date and OCR headline may overwrite or conflict with one another. ### Attack Path 1. An attacker obtains write access to a shared scan output directory. 2. The attacker predicts that the script will create `temp_image.pdf` or `enhanced_`. 3. The attacker creates that path as a symbolic link to another file writable by the victim process. ...[truncated 1019 chars]- Remediation
View remediation
