T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:282- Finding
Caller-Controlled Path Allows Arbitrary Local File Upload
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 140-151 and 282-290
Vulnerability Type: Missing file-type and sensitive-path validation
Risk Level: MediumComplete Code Snippet
python mime_type, _ = mimetypes.guess_type(file_path) if mime_type is None: mime_type = 'application/octet-stream' try: with open(file_path, 'rb') as f: files = { 'file': (os.path.basename(file_path), f, mime_type) } data = { 'ocr_type': ocr_type, } response = requests.post(url, headers=headers, data=data, files=files, timeout=60)python ocr_type = sys.argv[1] file_path = sys.argv[2] if ocr_type not in SUPPORTED_TYPES: sys.exit(f"Error: unsupported ocrType '{ocr_type}', available values: {', '.join(SUPPORTED_TYPES.keys())}") if not os.path.isfile(file_path): sys.exit(f"Error: file does not exist - {file_path}") config = load_config()Technical Analysis
The Skill declares that
IMAGE_TO_PPTaccepts an image, and its documentation identifies JPEG, PNG, BMP, TIFF, and WebP as supported formats. The implementation, however, only verifies that the supplied path points to a regular file.mimetypes.guess_type()is based on the filename extension and is not a security validation mechanism. Unknown files are explicitly accepted asapplication/octet-stream. The script does not:- Allowlist supported image extensions.
- Validate the file signature or decoded image format.
- Reject known-sensitive files or directories.
- Restrict input to an approved workspace.
- Request confirmation when a path is outside the expected input area.
Consequently, any file readable by the process can be submitted to the remote conversion endpoint if its path is supplied as the
filePathargument. This exceeds the minimum file-access scope required for an image-to-PPT conversion Skill.Attack Path
...[truncated 1041 chars]
- Remediation
View remediation
Remediation Suggestions
- Enforce an explicit allowlist of supported extensions such as
.jpg,.jpeg,.png,.bmp,.tif,.tiff, and.webp. - Validate actual file signatures using a maintained image parser rather than trusting extensions or
mimetypes. - Reject files that cannot be decoded as a supported image.
- Resolve the path with
Path.resolve()and, where practical, require it to reside under an approved upload or workspace directory. - Reject known-sensitive paths and filenames, including
.env, private-key files, credential stores, and configuration directories. - Require explicit user confirmation before uploading files outside the expected workspace.
- Enforce a reasonable maximum file size before opening and transmitting the file.
- Clearly notify the user that the selected file will be uploaded to an external service.
- Enforce an explicit allowlist of supported extensions such as
