T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/genome_manager.py:57- Finding
Path Traversal Allows Reading and Overwriting JSON Files Outside Genome Storage
- Content
View full analysis
- Remediation
View remediation
str: if not GENOME_NAME_PATTERN.fullmatch(name): raise ValueError("Invalid genome name") return name ``` 2. Resolve every target path and verify that it remains under the resolved genome directory: ```python def genome_path(name: str) -> Path: validate_genome_name(name) base = GENOMES_DIR.resolve() target = (base / f"{name}.json").resolve() if target.parent != base: raise ValueError("Genome path escapes the storage directory") return target ``` 3. Use this centralized path function for `create`, `get`, `mutate`, and `validate`. 4. Validate the `name` loaded from a parent genome before using it to construct a mutated output filename. 5. Reject absolute paths, `..`, forward slashes, backslashes, null bytes, and platform-specific path syntax even if a less restrictive naming policy is required. 6. Avoid silent overwrites. Use exclusive creation mode (`"x"`) for new genomes or require an explicit overwrite option. 7. Where overwriting is supported, use an atomic temporary-file write followed by a controlled rename within the validated storage directory. 8. Add tests covering absolute paths, nested paths, repeated traversal sequences, Windows-style separators, symlink-related edge cases, and malicious `name` fields loaded from JSON. ]]>
