T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/app.py:164- Finding
Unrestricted Local File Read and Write Through Unauthenticated API Endpoints
- Content
View full analysis
- Remediation
View remediation
Path: candidate = (WORKSPACE / user_path).resolve() try: candidate.relative_to(WORKSPACE) except ValueError: raise PermissionError("Path is outside the permitted workspace") return candidate ``` 3. Reject absolute paths unless a file was explicitly selected through a trusted local workflow. 4. Restrict readable and writable extensions to the formats genuinely required by the editor. 5. Prevent symlink escapes by validating resolved targets and, where appropriate, refusing symlinks. 6. Disable global CORS. If cross-origin access is necessary, allow only an explicit trusted origin. 7. Generate an unpredictable session token at startup and require it on every API request. 8. Validate `Origin` and `Host` headers and add CSRF protection to state-changing endpoints. 9. Use atomic writes and avoid automatically creating arbitrary parent directories. 10. Run the server under an account with minimal filesystem privileges. ]]>
