T09 · Insecure Skill Coding Practices
- Location
scripts/imap.js:14- Finding
Attachment download whitelist can be bypassed through symbolic-link directories
- Content
View full analysis
path.resolve(d.replace(/^~/, os.homedir())) ); const allowed = allowedDirs.some(dir => resolved === dir || resolved.startsWith(dir + path.sep) ); if (!allowed) { throw new Error(`Access denied: '${dirPath}' is outside allowed write directories`); } return resolved; } ``` The validated directory is then used for attachment writes: ```javascript const resolvedDir = validateWritePath(outputDir); if (!fs.existsSync(resolvedDir)) { fs.mkdirSync(resolvedDir, { recursive: true }); } const downloaded = []; for (const attachment of parsed.attachments) { if (specificFilename && attachment.filename !== specificFilename) { continue; } if (attachment.content) { const filePath = path.join(resolvedDir, sanitizeFilename(attachment.filename)); fs.writeFileSync(filePath, attachment.content); downloaded.push({ filename: attachment.filename, path: filePath, size: attachment.size, }); } } ``` `path.resolve()` normalizes path components but does not resolve symbolic links. Consequently, a path that lexically appears beneath an allowed directory may resolve through a symbolic link to an arbitrary directory outside the whitelist. The attachment filename is reduced to a basename, which prevents direct `../` traversal but does not address a symbolic link in the directory path. It also doe ...[truncated 1658 chars]- Remediation
View remediation
