Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The delete-all command recursively deletes every file and subdirectory under a user-supplied --data-dir and then attempts to remove the directory itself, with no restriction that the path must be the application's expected data directory. If this script is invoked by an agent or wrapper that forwards user-controlled arguments, an attacker or mistaken user could point it at arbitrary filesystem locations and cause destructive data loss far beyond the sleep-profile scope.
