T09 · Insecure Skill Coding Practices
- Location
founder_ledger.py:143- Finding
Ledger Files May Be Created with Overly Broad Permissions
- Content
View full analysis
Vulnerability Details
File Location:
founder_ledger.py:143-144
Vulnerability Type: Insecure file permissions exposing plaintext financial data
Risk Level: Lowpython def save(path: Path, ledger: Ledger) -> None: path.write_text(json.dumps(ledger.to_json(), indent=2) + "\n")Technical Analysis
The application stores ledger amounts, dates, descriptions, and revenue sources in plaintext JSON. When the destination does not already exist,
Path.write_text()creates it using permissions derived from the process umask rather than explicitly enforcing owner-only access.With a common
022umask, a newly created ledger can receive mode0644, making it readable by other local users. The code does not subsequently restrict the file to mode0600. Exploitation requires another account on the same system to have traversal access to the ledger's parent directories and read access granted by the resulting mode.Attack Path
- A user runs an operation that saves a new ledger, such as
python3 founder_ledger.py add 5 "Customer payment". save()createsledger.jsonthroughPath.write_text().- The operating system applies the current process umask. Under a typical
022umask, the resulting file may be mode0644. - Another local user who can traverse the parent directory opens the ledger file.
- That user reads the victim's amounts, transaction dates, descriptions, revenue sources, and milestone history.
Impact Assessment
This flaw can cause local confidentiality loss for the selected ledger file. An attacker may obtain sensitive business and financial records but does not gain code execution, elevated privileges, or remote access through this issue alone. The practical scope depends on the host's user model, umask, directory permissions, and any pre-existing permissions on the destination file.
- A user runs an operation that saves a new ledger, such as
- Remediation
View remediation
Remediation Suggestions
- Create new ledger files with explicit owner-only permissions, such as mode
0600, instead of relying on the process umask. - Write updates to a same-directory temporary file created securely with
tempfile.mkstemp()or an equivalent exclusive-create operation. - Apply mode
0600to the temporary file, flush buffered data, and callos.fsync()before atomically replacing the destination withos.replace(). - Consider rejecting symbolic-link destinations where the application should only operate on regular files.
- Verify and, where appropriate, tighten permissions on existing ledger files before writing.
- Document that ledger contents are plaintext and should be stored in a private directory protected by restrictive permissions.
- Create new ledger files with explicit owner-only permissions, such as mode
