T09 · Insecure Skill Coding Practices
- Location
scripts/utils/imap.js:674- Finding
Path Traversal Through Untrusted Email Attachment Filenames
- Content
View full analysis
``` 4. `mailparser` exposes the attacker-controlled attachment filename. 5. `path.join(dir, att.filename)` constructs a path outside the intended attachment directory. 6. `fs.writeFileSync` creates or overwrites the resulting file with attacker-controlled data. 7. If the overwritten file is later interpreted or executed, the attacker may achieve configuration corruption or code execution in the user's context. ### Impact Assessment The immediate impact is arbitrary file creation or overwrite within the current process user's filesystem permissions. This does not directly grant elevated operating-system privileges, but it can compromise project files, configuration files, scripts, or other ...[truncated 114 chars]- Remediation
View remediation
