T09 · Insecure Skill Coding Practices
- Location
scripts/start-server.js:55- Finding
Arbitrary Local File Disclosure Through Directory Traversal
- Content
View full analysis
{ if (err) { res.writeHead(404); res.end('Not Found'); return; } const contentType = mimeTypes[ext] || 'application/octet-stream'; res.writeHead(200, { 'Content-Type': contentType }); res.end(data); }); ``` ### Technical Analysis The server uses the request URL as a filesystem path and passes it to `path.join()` without first restricting it to an approved static directory. It does not canonicalize and validate the resulting path against an allowed root. Traversal components such as `../` can therefore cause the normalized path to escape `skillDir`. If the HTTP client preserves traversal components in the request path, `fs.readFile()` can read any file accessible to the Node.js process. The implementation also serves files from the entire project root rather than limiting access to the declared `assets` directory. There is no allowlist of static resources. ### Attack Path 1. The attacker obtains network access to the HTTP server. 2. The attacker sends a request containing preserved traversal segments, for example using a client option that does not normalize the URL path. 3. `path.join(skillDir, filePath)` resolves the traversal outside the project directory. 4. `fs.readFile()` opens the resulting operating-system path. 5. The server returns the file contents in the HTTP response. The exact number of traversal segments depends on the installation path and the target file. ### Impact Assessment An unauthenticated attacker may read files available to the Node.js process. Depending on the host configuration, this may expose: - Application source and configuration files - Environment or ...[truncated 245 chars]- Remediation
View remediation
