T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/main.py:91- Finding
Unrestricted Local File Upload to an External OCR Service
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 91-112
Vulnerability Type: Arbitrary local file disclosure through insufficient input validation
Risk Level: HighTechnical Analysis
The
filePathargument is accepted as long as it points to a regular file. The implementation does not verify that the supplied file is a supported image or PDF, inspect its content signature, reject symbolic links, enforce a maximum size, or restrict access to a user-approved directory.The MIME type is inferred only from the filename. If it cannot be inferred, the file is uploaded as
application/octet-stream. Consequently, any regular file readable by the Skill process can be transmitted to the configured OCR server.python # 检查文件是否存在 if not os.path.isfile(file_path): sys.exit(f"错误: 文件不存在 - {file_path}") # 自动检测 MIME 类型 mime_type, _ = mimetypes.guess_type(file_path) if mime_type is None: mime_type = 'application/octet-stream' headers = { 'Authorization': f'Bearer {api_key}' } try: with open(file_path, 'rb') as f: files = { 'file': (os.path.basename(file_path), f, mime_type) } data = { 'ocrType': ocr_type, 'channelTag': "scnetSkills" } response = requests.post(url, headers=headers, data=data, files=files, timeout=60)Uploading a user-selected document is necessary for the declared hosted OCR functionality. However, permitting arbitrary Agent-readable files exceeds the minimum file-access scope needed to process ride-hailing itinerary images and PDFs.
Attack Path
- An attacker or untrusted prompt persuades the Agent to invoke the Skill with a sensitive local path instead of a legitimate itinerary.
- The Skill checks only whether the path references a regular file.
- The Skill opens the file using the permissions of its host process.
- The complete file is placed in a m ...[truncated 689 chars]
- Remediation
View remediation
Remediation Suggestions
- Allowlist only the file formats required by the OCR service, such as PDF, JPEG, and PNG.
- Validate the file's content signature rather than trusting its extension or inferred MIME type.
- Resolve the path with
Path.resolve()and restrict it to an explicitly approved upload or workspace directory. - Reject symbolic links and non-regular files, and verify the resolved file immediately before opening it.
- Enforce a conservative maximum file size before reading or uploading the file.
- Require explicit user confirmation that the selected file will be sent to a third-party OCR service.
- Clearly disclose the types of personal information potentially contained in itinerary documents and refer users to the service provider's retention and privacy terms.
- If arbitrary paths must be supported, use a trusted host-provided file-selection or attachment mechanism rather than accepting unverified prompt-derived paths.
