T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/deploy-agent.sh:27- Finding
Path Traversal Enables Unauthorized State File Access and Deletion
- Content
View full analysis
"$file" log "State saved for: $name" } ``` The same unsafe path is used when initializing and cancelling deployments: ```bash local state_file=$(get_state_file "$name") if [ -f "$state_file" ]; then error "Deployment '$name' already exists. Use 'deploy-agent status $name' or 'deploy-agent cancel $name'" exit 1 fi cat > "$state_file" <- Remediation
View remediation
