T05 · Unauthorized Access and Privilege Escalation
- Location
handler.js:285- Finding
Arbitrary Local File Disclosure Through Unrestricted logPath
- Content
View full analysis
0 && lines[lines.length - 1] === "") { lines.pop(); } return lines; } ``` ```js function resolveSessionLike(input) { if (input && typeof input.sessionId === "string" && input.sessionId.trim()) { return readSession(input.sessionId.trim()); } if (input && typeof input.logPath === "string" && input.logPath.trim()) { return { sessionId: null, command: null, commandPid: null, workerPid: null, status: "unknown", startedAt: null, endedAt: null, logPath: input.logPath.trim() }; } throw new Error("sessionId or logPath is required"); } ``` ```js async function long_context_shell_peek(input = {}) { const session = resolveSessionLike(input); return buildStatusCard(session, input); } async function long_context_shell_scan(input = {}) { const session = resolveSessionLike(input); ``` ### Technical Analysis The `long_context_shell_peek` and `long_context_shell_scan` APIs accept an arbitrary caller-provided `logPath`. `resolveSessionLike` stores the path without validating its location, ownership, file type, or relationship to the expected runtime log directory. The value subsequently reaches `readLines`, which reads the supplied path with `fs.readFileSync`. There is no canonicalization with `realpath`, directory-containment check, allowlist, or symlink protection. Although the parameter is described as a direct path to a log file, the implementation does not enforce that the target is a log beneath `LOG_DIR`. Consequently, any local fil ...[truncated 1502 chars]- Remediation
View remediation
