T09 · Insecure Skill Coding Practices
- Location
modules/tagger.py:104- Finding
Path Traversal in Context Tagging Enables Unauthorized JSON Modification
- Content
View full analysis
`. Exploitation requires the selected source to exist and contain valid JSON. The method then adds `tags` and `keywords` fields and writes the resulting document to the traversal-selected destination. ### Attack Path 1. The attacker identifies a readable JSON file and a writable destination accessible to the process. 2. The attacker constructs a `context_id` containing sufficient `../` components to escape the configured knowledge-base directories. 3. The attacker invokes the CLI `tag` command or calls `MeaningTagger.tag()` directly. 4. `_update_context()` resolves the source p ...[truncated 994 chars]- Remediation
View remediation
Path: parent = parent.resolve() candidate = (parent / filename).resolve() if not candidate.is_relative_to(parent): raise ValueError("Path escapes the permitted directory") return candidate ``` 3. Reject absolute paths, path separators, `.` and `..` components, null bytes, and unexpected extensions. 4. Generate context identifiers internally rather than accepting arbitrary identifiers where possible. 5. Account for symlink escapes by validating canonical resolved paths immediately before access. 6. Avoid creating arbitrary parent directories from user-derived paths. 7. Add tests covering absolute paths, nested traversal, mixed separators, encoded traversal, and symlink-based escapes. ]]>
