T09 · Insecure Skill Coding Practices
- Location
core/image.py:43- Finding
Arbitrary Local File Disclosure Through Image Parameters
- Content
View full analysis
bool: """Check if a string value is a local file path.""" if not isinstance(value, str): return False if value.startswith(("http://", "https://", "data:")): return False path = Path(value) return path.exists() and path.is_file() def file_to_base64(file_path: str) -> str: """Convert a local file to base64 data URI. Args: file_path: Path to the local file Returns: Base64 data URI string (e.g., "data:image/png;base64,...") """ path = Path(file_path) mime_type, _ = mimetypes.guess_type(str(path)) if mime_type is None: mime_type = "image/png" with open(path, "rb") as f: data = base64.b64encode(f.read()).decode("utf-8") return f"data:{mime_type};base64,{data}" ``` ```python def convert_image_value(value: Any) -> Any: """Convert image parameter value, handling local file paths. Args: value: Parameter value (string or list of strings) Returns: Converted value with local files as base64 data URIs """ if isinstance(value, str): if is_local_file(value): return file_to_base64(value) return value elif isinstance(value, list): return [convert_image_value(v) for v in value] return value ``` ```python def process_image_params(body: dict[str, Any]) -> dict[str, Any]: """Process request body, converting local file paths to base64. Args: body: Request body dictionary Returns: Processed body with image params converted """ result = body.copy() for key in IMAGE_PARAM_NAMES: if key in result: result[key] = conver ...[truncated 2726 chars]- Remediation
View remediation
