T09 · Insecure Skill Coding Practices
- Location
scripts/import_notes.py:258- Finding
Path Traversal Allows Reads and Writes Outside the Notes Directory
- Content
View full analysis
- Remediation
View remediation
Path: root = root.resolve() candidate = (root / filename).resolve() if not candidate.is_relative_to(root): raise ValueError("Path escapes the permitted directory") return candidate ``` 3. Apply confinement independently to: - Source book files. - Imported book files. - Export destinations. - User-configurable base directories. 4. Do not accept arbitrary export destinations by default. Restrict outputs to a dedicated export directory unless the user explicitly authorizes a destination after displaying its resolved path. 5. Use `mkdir(parents=True, exist_ok=True)` only after confirming that the resolved directory is permitted. 6. Use atomic writes: - Create a temporary file inside the destination directory. - Flush and synchronize it. - Replace the destination atomically. 7. Add tests covering traversal payloads, absolute paths, symbolic links, Windows drive paths, and mixed path separators. ]]>
