T05 · Unauthorized Access and Privilege Escalation
- Location
knowledge-base/kb-manager.py:34- Finding
Business Name Path Traversal Enables Filesystem Escape and Recursive Directory Deletion
- Content
View full analysis
Vulnerability Details
File Location:
knowledge-base/kb-manager.py:34-36,knowledge-base/kb-manager.py:41-47, andknowledge-base/kb-manager.py:114-121
Vulnerability Type: Path traversal leading to unauthorized filesystem access and recursive deletion
Risk Level: HighVulnerable Code
python def get_business_dir(business_name: str) -> str: """获取业务数据库目录""" return os.path.join(KB_ROOT, business_name)python def ensure_business(business_name: str) -> Dict[str, Any]: """确保业务存在,不存在则创建""" businesses = load_businesses() if business_name not in businesses["businesses"]: # 创建新业务 business_dir = get_business_dir(business_name) os.makedirs(business_dir, exist_ok=True)python def delete_business(business_name: str) -> Dict[str, Any]: """删除业务""" businesses = load_businesses() if business_name not in businesses["businesses"]: return {"status": "not_found", "message": f"业务「{business_name}」不存在"} business_dir = get_business_dir(business_name) # 删除目录 import shutil if os.path.exists(business_dir): shutil.rmtree(business_dir)Technical Analysis
business_nameis taken from command-line or Agent-controlled input and passed directly toos.path.join()without validation or canonical-path containment checks.This does not guarantee that the resulting path remains under
KB_ROOT:- A value containing
../can traverse to a parent directory. - An absolute path causes
os.path.join()to discardKB_ROOT. - The resulting uncontrolled path is used for directory creation, database reads and writes, enumeration, and recursive deletion.
Although
delete_business()first checks whether the supplied name exists inbusinesses.json, an attacker may create a malicious business entry throughensure_business()and subsequently delete it. A preexist ...[truncated 1455 chars]- A value containing
- Remediation
View remediation
Remediation Suggestions
-
Validate business names using a conservative allowlist, such as letters, numbers, underscores, and hyphens.
-
Reject absolute paths, path separators, empty names,
.components, and..components. -
Resolve the target and root directories before every filesystem operation and enforce containment:
python from pathlib import Path KB_ROOT_PATH = Path(__file__).resolve().parent def get_business_dir(business_name: str) -> Path: if not business_name or Path(business_name).name != business_name: raise ValueError("Invalid business name") target = (KB_ROOT_PATH / business_name).resolve() if target.parent != KB_ROOT_PATH: raise ValueError("Business path escapes KB root") return target -
Do not trust path-related values loaded from
businesses.json; validate them again before use. -
Require explicit confirmation or a separate authorization control for recursive deletion.
-
Refuse to recursively delete symbolic links or paths that are not direct children of
KB_ROOT. -
Consider replacing recursive deletion with a restricted quarantine or soft-delete mechanism.
-
