T09 · Insecure Skill Coding Practices
- Location
scripts/pipeline.sh:458- Finding
Arbitrary-Path Recursive Deletion Through an Unvalidated Version Label
- Content
View full analysis
/dev/null || true cp "$EXPORT_DIR/voice_test_results.json" "$ARCHIVE/" 2>/dev/null || true cp "$EXPORT_DIR/probe_results.json" "$ARCHIVE/" 2>/dev/null || true # Archive prepared data snapshot (train/eval JSONL + stats.json) # Remove first to prevent nesting when the same version is re-archived rm -rf "$ARCHIVE/data" ``` ### Technical Analysis The pipeline accepts `--version` as a user-controlled string and appends it directly to: ```text $BASE_DIR/adapters/$VERSION ``` No regular-expression validation, canonicalization, or containment check is applied before recursive deletion. A version containing `../` path components can cause `ARCHIVE` to resolve outside the intended `adapters` directory. Quoting the variable prevents shell word splitting but does not prevent filesystem path traversal. The two `rm -rf` operations consequently act on attacker-selected directories named `adapter_weights` and `data`. Symbolic-link and unusual `--base-dir` arrangements can further complicate the effective deletion boundary because the target is not resolved and verified immediately before deletion. ### Attack Path 1. An attacker or unsafe automation invokes the pipeline with a crafted version: ```bash bash scripts/pipeline.sh \ --slug victim \ --model example/model \ --source ./training \ --version ../../../target ``` 2. The s ...[truncated 894 chars]- Remediation
View remediation
