T05 · Unauthorized Access and Privilege Escalation
- Location
src/prompt-db.js:6- Finding
Prompt Pack Path Traversal Enables Unauthorized JSON File Read and External Disclosure
- Content
View full analysis
({ prompt })) }; } const packs = Array.isArray(promptPack) ? promptPack : [promptPack]; const records = packs.flatMap((pack) => readPack(pack)); ``` ### Technical Analysis `config.promptPack` and `config.promptPacks` are used as path components without validating them against the list of supported packs. `path.join()` normalizes traversal sequences but does not guarantee that the resulting path remains beneath `prompt-db/`. A value containing `../` can therefore resolve to a readable JSON file outside `prompt-db/`. If the selected file contains a compatible array of prompt records, its data is processed as prompts. The application then sends those prompt values to the configured OpenAI-compatible, Anthropic, or OpenRouter-compatible endpoint. This creates both a local file access violation and a potential external disclosure channel. The file must be valid JSON and structurally compatible with the expected prompt-pack format, which limits—but does not eliminate—the exploitability. ### Attack Path 1. An attacker supplies or modifies a tracker configuration file. 2. The attacker sets `promptPack` or an element of `promptPacks` to a traversal path such as `../../some-directory/sensitive-data`. 3. `readPack()` appends `.json ...[truncated 748 chars]- Remediation
View remediation
