T09 · Insecure Skill Coding Practices
- Location
scripts/generate-pdf-report.sh:5- Finding
Path Traversal Through Unsanitized Report Filename
- Content
View full analysis
<公司名>" exit 1 fi mkdir -p "$REPORT_DIR" # 1. 生成 HTML 报告 HTML_FILE="$REPORT_DIR/${COMPANY_NAME}_${STOCK_CODE}.html" cat > "$HTML_FILE" << EOF ``` ### Technical Analysis The script directly incorporates the user-controlled `COMPANY_NAME` and `STOCK_CODE` arguments into a filesystem path. It does not reject path separators, `..` components, control characters, or absolute-path-like input. Shell quoting prevents word splitting and shell command injection, but it does not prevent filesystem path traversal. For example, a company name containing `../../target` causes the resulting path to resolve outside the intended report directory. A related pattern exists in `scripts/analyze.sh:24-40`, where `STOCK_CODE` is used in cache filenames without validation: ```bash "$SCRIPT_DIR/fetch-eastmoney.sh" "$STOCK_CODE" price > "$OUTPUT_DIR/price_${STOCK_CODE}.json" "$SCRIPT_DIR/fetch-eastmoney.sh" "$STOCK_CODE" financial > "$OUTPUT_DIR/financial_${STOCK_CODE}.json" "$SCRIPT_DIR/fetch-ths.sh" "$STOCK_CODE" financial > "$OUTPUT_DIR/ths_${STOCK_CODE}.txt" "$SCRIPT_DIR/fetch-research.sh" "$STOCK_CODE" all > "$OUTPUT_DIR/research_${STOCK_CODE}.txt" "$SCRIPT_DIR/fetch-eastmoney.sh" "$STOCK_CODE" holder > "$OUTPUT_DIR/holder_${STOCK_CODE}.json" ``` The generated report has a fixed `.html` suffix, and cache files have fixed suffixes, which limits—but does not eliminate—the ability to overwrite arbitrary files. ### Attack Path 1. An attacker invokes the report-generation entry point with a company name or stock code containing traversal components. 2. The input is concatenated with `/app/skills/stock-analysis/reports` with ...[truncated 1180 chars]- Remediation
View remediation
&2 exit 1 fi SAFE_COMPANY=$(printf '%s' "$COMPANY_NAME" | tr -cd '[:alnum:]_.-') if [ -z "$SAFE_COMPANY" ]; then echo "Invalid company name" >&2 exit 1 fi HTML_FILE="$REPORT_DIR/${SAFE_COMPANY}_${STOCK_CODE}.html" ``` Canonical containment checks should still be added rather than relying solely on character replacement. ]]>
