T09 · Insecure Skill Coding Practices
- Location
scripts/init_project.sh:5- Finding
Unrestricted Project Path Permits Directory Traversal and Unsafe File Overwrite
- Content
View full analysis
Vulnerability Details
File Location:
scripts/init_project.sh, lines 5–6 and 17–70
Vulnerability Type: Path traversal, symlink following, and arbitrary writable-file overwrite
Risk Level: MediumVulnerable Code
bash PROJECT_NAME="$1" TARGET_DIR="$2" if [ -z "$PROJECT_NAME" ] || [ -z "$TARGET_DIR" ]; then echo "Usage: $0 <project_name> <target_directory>" exit 1 fi echo "Initializing new project: $PROJECT_NAME in $TARGET_DIR" # Create project directory if it doesn't exist mkdir -p "$TARGET_DIR/$PROJECT_NAME" # Create standard project structure mkdir -p "$TARGET_DIR/$PROJECT_NAME"/{src,tests,docs,config} # Create basic README cat > "$TARGET_DIR/$PROJECT_NAME/README.md" << EOF # $PROJECT_NAME ## Description Brief description of the project goes here. ## Setup Instructions for setting up the project locally. ## Usage How to run and use the project. ## Contributing Guidelines for contributing to the project. EOF # Create a basic .gitignore if git is available if command -v git >/dev/null 2>&1; then cd "$TARGET_DIR/$PROJECT_NAME" git init cat > .gitignore << EOF # Dependencies node_modules/ __pycache__/ *.pyc *.pyo *.pyd .Python env/ venv/ .venv/ # Build outputs build/ dist/ *.egg-info/ *.so # Logs *.log logs/ # Environment variables .env .env.local # OS generated files .DS_Store Thumbs.db EOF fi echo "Project $PROJECT_NAME initialized successfully in $TARGET_DIR"Technical Analysis
The script directly combines the caller-controlled
TARGET_DIRandPROJECT_NAMEvalues without validating or canonicalizing either path. Although the variables are quoted, quoting only prevents shell word splitting and ordinary shell metacharacter injection; it does not prevent filesystem traversal.A
PROJECT_NAMEcontaining components such as../can resolve outside the intended target directory. The script then creates directories, initializes a Git repository, and writesREADME.mdand.gitignoreat the re ...[truncated 1579 chars]- Remediation
View remediation
Remediation Suggestions
-
Restrict
PROJECT_NAMEto a single safe path component using an allowlist, for example:bash if [[ ! "$PROJECT_NAME" =~ ^[A-Za-z0-9][A-Za-z0-9._-]*$ ]] || [[ "$PROJECT_NAME" == "." || "$PROJECT_NAME" == ".." ]]; then echo "Invalid project name" >&2 exit 1 fi -
Reject project names containing
/, absolute paths, traversal components, control characters, or leading option syntax. -
Canonicalize the target root and computed destination, then verify that the destination remains beneath the canonical target root before performing any filesystem operation.
-
Add option terminators to relevant commands:
bash mkdir -p -- "$DESTINATION" cd -- "$DESTINATION" || exit 1 -
Refuse to operate on an existing project destination by default. Require an explicit, clearly documented overwrite option if replacement is necessary.
-
Reject symbolic links before writing template files. Prefer exclusive file creation with no-follow behavior rather than shell redirection where supported.
-
Enable strict shell error handling and check every operation:
bash set -euo pipefail -
Apply restrictive creation permissions where appropriate, such as setting a suitable
umask, so generated files are not more broadly accessible than intended.
-
