T09 · Insecure Skill Coding Practices
- Location
scripts/cache_clear.sh:37- Finding
Path Traversal in Cache Key Allows Deletion of JSON Files Outside the Cache Directory
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac target="${CACHE_DIR}/${MODE}.json" cache_root=$(realpath -m -- "${CACHE_DIR}") resolved_target=$(realpath -m -- "${target}") case "${resolved_target}" in "${cache_root}"/*.json) ;; *) echo "ERROR: Target is outside the cache directory" >&2 exit 1 ;; esac if [[ -f "${resolved_target}" ]]; then rm -f -- "${resolved_target}" fi ``` Additional hardening should include: - Prefer an explicit allowlist of known cache keys. - Use `--` before path operands passed to file utilities. - Reject arguments containing `/`, `\`, `..`, or control characters. - Add regression tests for absolute paths and traversal sequences. ]]>
