T09 · Insecure Skill Coding Practices
- Location
scripts/publish.mjs:128- Finding
Markdown Image Paths Can Read and Upload Files Outside the Article Directory
- Content
View full analysis
]*src="([^"]+\.(png|jpg|jpeg|gif|webp))"[^>]*>/gi; let result = html; for (const match of [...html.matchAll(imgRegex)]) { const src = match[1]; if (src.startsWith("http")) continue; const wxUrl = await uploadInlineImage(path.resolve(mdDir, src), accessToken); result = wxUrl ? result.replace(src, wxUrl) : result.replace(match[0], `[Image load failed]
`); } return result; } ``` ### Technical Analysis The source path of each rendered image is derived from article content and resolved with `path.resolve(mdDir, src)`. The resulting path is not checked to ensure that it remains inside the Markdown article directory or another explicitly authorized asset directory. Consequently, absolute paths and paths containing `../` components can escape `mdDir`. The program then reads the resolved file with `fs.readFileSync()` and uploads its contents to the WeChat media API. File type handling relies solely on the filename suffix and does not validate the actual file format. The exploitable scope is limited to files readable by the publishing process whose path ...[truncated 1469 chars]- Remediation
View remediation
