T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_trend.py:250- Finding
Output Path Traversal Through Unsanitized Stock Name
- Content
View full analysis
Vulnerability Details
File Location:
scripts/analyze_trend.py, lines 250-252 and 271-272
Vulnerability Type: Path traversal and unintended file overwrite
Risk Level: MediumVulnerable Code
python report_file = output_path / f"{stock_name}_趋势分析_{datetime.now().strftime('%Y%m%d')}.md" with open(report_file, "w", encoding="utf-8") as f: f.write(report)python data_file = output_path / f"{stock_name}_技术指标.csv" df_with_indicators.to_csv(data_file, index=False, encoding="utf-8-sig")Technical Analysis
The user-controlled
stock_namevalue is incorporated directly into two output paths without normalization or validation. The value can originate from the command-line--nameargument and may contain parent-directory components such as../, path separators, or an absolute path.pathlib.Pathdoes not confine the resulting path tooutput_path. Parent-directory components are resolved by the operating system during file access, while an absolute right-hand path can supersede the intended base directory. Both output operations use overwrite-capable behavior, so an existing file with the generated path can be replaced.Exploitation is constrained by the fixed report and CSV filename suffixes and by the permissions of the process. Nevertheless, the intended output-directory boundary can be bypassed.
Attack Path
- The attacker or untrusted caller supplies a crafted stock name through
--name. - For example, a value containing
../targetis passed to the application. - The application constructs paths such as
trend_reports/../target_technical-indicators.csvand a date-suffixed Markdown report path. - The operating system resolves the parent-directory component outside
trend_reports. - The application creates or overwrites the resulting files if its process account has permission to do so.
Impact Assessment
An attacker can cause Markdown and CSV outp ...[truncated 448 chars]
- The attacker or untrusted caller supplies a crafted stock name through
- Remediation
View remediation
Remediation Suggestions
- Treat
stock_nameas a display value rather than a filesystem path. - Reject absolute paths,
.and..path components, directory separators, control characters, and platform-specific reserved characters. - Convert the supplied name to a conservative filename token, such as characters from an explicit allowlist.
- Resolve both the output directory and candidate destination, then verify that the destination remains beneath the resolved output directory.
- Use exclusive file creation mode when replacing existing reports is not required.
- Keep the original stock name only inside report content and use a separately generated safe identifier for filenames.
Example confinement logic:
python import re from pathlib import Path output_root = Path(output_dir).resolve() output_root.mkdir(parents=True, exist_ok=True) safe_name = re.sub(r"[^A-Za-z0-9._-]", "_", stock_name) if not safe_name or safe_name in {".", ".."}: raise ValueError("Invalid stock name") report_file = ( output_root / f"{safe_name}_trend_analysis_{datetime.now().strftime('%Y%m%d')}.md" ).resolve() if output_root not in report_file.parents: raise ValueError("Output path escapes the configured directory")- Treat
