T09 · Insecure Skill Coding Practices
- Location
toolkit/src/content-adapter.ts:211- Finding
Arbitrary Local File Disclosure Through Feature Image Metadata
- Content
View full analysis
{ const resolvedPath = resolve(filePath); if (!existsSync(resolvedPath)) { throw new Error(`Feature image file not found: ${resolvedPath}`); } const filename = basename(resolvedPath); const content = readFileSync(resolvedPath); const response = await postJson>( '/ghost/uploadImage', { filename, contentBase64: content.toString('base64'), contentType: detectMimeType(filename), }, ``` ### Technical Analysis A Markdown document can specify `featureImage`, `image`, or `ghost.featureImage` in YAML frontmatter. Non-HTTP values are treated as local file paths. The publishing pipeline resolves those paths relative to the Markdown file but does not ensure that the resulting path remain ...[truncated 1800 chars]- Remediation
View remediation
