T09 · Insecure Skill Coding Practices
- Location
scripts/get_stock_history.py:49- Finding
Path Traversal Through Unsanitized Output Filename Components
- Content
View full analysis
2 else None end_date = sys.argv[3] if len(sys.argv) > 3 else None adjust = sys.argv[4] if len(sys.argv) > 4 else "qfq" get_stock_history(symbol, start_date, end_date, adjust) ``` ### Technical Analysis The `symbol`, `start_date`, and `end_date` values originate from command-line arguments and are used directly to construct `output_file`. No validation restricts these values to their documented formats, and no check ensures that the resolved output path remains within an approved directory. An attacker who can control the script arguments can include absolute paths, path separators, or traversal sequences such as `../`. Python's `DataFrame.to_csv()` then creates or truncates the resulting path. Although the fixed separators and `.csv` suffix limit exact filename selection, an attacker can still redirect output to an unintended writable directory and overwrite a file whose resulting name matches the constructed path. ### Attack Path 1. The attacker obtains the ability to invoke the script or influence its command-line arguments. 2. The attacker supplies a `symbol`, `start_date`, or `end_date` containing an absolute path or traversal components. 3. The values are passed unchanged to `get_stock_history()`. 4. The script interpolates the attacker-controlled values into `output_file`. 5. `df.to_csv()` creates or truncates that path using the privileges of the Python process. 6. Financial CSV content ...[truncated 672 chars]- Remediation
View remediation
