T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/tool-registry.mjs:286- Finding
Missing Runtime Authorization Allows Unrestricted File Access and Command Execution
- Content
View full analysis
{ const fs = await import('fs'); const path = await import('path'); const filePath = typeof input === 'string' ? input : input.path; if (!filePath) throw new Error('path required'); const content = fs.readFileSync(filePath, 'utf-8'); return { path: filePath, content, size: content.length }; } ``` They also include unrestricted file writes: ```javascript execute: async (ctx, input) => { const fs = await import('fs'); const path = await import('path'); const { file: filePath, content } = typeof input === 'string' ? JSON.parse(input) : input; if (!filePath || content === undefined) throw new Error('file and content required'); fs.writeFileSync(filePath, content, 'utf-8'); return { path: filePath, bytes: content.length }; } ``` Finally, the registry exposes arbitrary operating-system command execution: ```javascript execute: async (ctx, input) => { const { spawn } = await import('child_process'); const comman ...[truncated 3671 chars]- Remediation
View remediation
