T09 · Insecure Skill Coding Practices
- Location
scripts/search_by_company_name.js:32- Finding
Company lookup results are stored in an insecure shared temporary directory
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search_by_company_name.js, lines 32-41
Vulnerability Type: Predictable and insufficiently protected temporary-file storage
Risk Level: MediumVulnerable Code
js function saveResult(companyName, json) { const ts = new Date().toISOString().slice(0, 19).replace(/[:-]/g, ""); const safeName = companyName.replace(/[^a-zA-Z0-9\u4e00-\u9fa5_-]/g, "_").slice(0, 60) || "company"; const fileName = `easy_search_company_name_${safeName}_${ts}.json`; const outputDir = path.join(os.tmpdir(), "ora-contact-pro"); fs.mkdirSync(outputDir, { recursive: true }); const filePath = path.join(outputDir, fileName); fs.writeFileSync(filePath, JSON.stringify(json, null, 2), "utf-8"); return { fileName, filePath }; }Technical Analysis
The function writes the complete company lookup response into a fixed directory under the operating system's shared temporary location. It does not specify restrictive permissions for either the directory or the result file, so effective permissions depend on the process umask and host configuration. On common configurations, the resulting JSON file may be readable by other local users.
The directory name and result filename are predictable from the supplied company name and the current timestamp. The implementation also uses normal file creation rather than exclusive creation and does not verify whether the directory or destination is controlled through symbolic links. If an attacker can pre-create the fixed temporary directory or a predicted destination entry, the write may be redirected.
The stored response may contain employee names, email addresses, telephone numbers, physical addresses, social-media profiles, and other contact information.
Attack Path
- A local attacker identifies the fixed
/tmp/ora-contact-prooutput location. - The attacker monitors that directory or pre-creates it before the victi ...[truncated 1156 chars]
- A local attacker identifies the fixed
- Remediation
View remediation
Remediation Suggestions
- Create a unique private directory for every invocation with
fs.mkdtempSync()rather than reusing a fixed shared directory. - Set the output directory mode to
0700and each result file to0600. - Open the result with exclusive creation, such as
flag: "wx", to prevent overwriting an existing destination. - Use
fs.lstatSync()or secure descriptor-based operations to reject symbolic links and unexpected filesystem object types. - Verify that the created directory is owned by the current user.
- Remove the result file and per-run directory immediately after the Agent consumes the response.
- Where practical, avoid persistent storage entirely and return the parsed response through standard output or an authenticated in-memory channel.
- Create a unique private directory for every invocation with
