T09 · Insecure Skill Coding Practices
- Location
scripts/translation_handler.py:39- Finding
Unvalidated Translation Request ID Allows Arbitrary JSON File Overwrite
- Content
View full analysis
list: """获取待翻译的请求""" ensure_dirs() requests = [] for f in QUEUE_DIR.glob("*.json"): try: with open(f, 'r', encoding='utf-8') as fp: data = json.load(fp) data['file_path'] = str(f) requests.append(data) except: pass return requests def submit_translation_result(request_id: str, translated_text: str): """提交翻译结果""" result_file = RESULT_DIR / f"{request_id}.json" with open(result_file, 'w', encoding='utf-8') as f: json.dump({ "translated": translated_text, "timestamp": datetime.utcnow().isoformat() }, f, ensure_ascii=False) ``` ```python def mark_translated(request: dict, translation: str): """ 标记翻译完成 Args: request: 请求字典(来自 check_and_translate) translation: 翻译后的文本 """ submit_translation_result(request['request_id'], translation) if 'file_path' in request: cleanup_request(request['file_path']) ``` ### Technical Analysis Translation queue files are parsed as JSON without validating their structure or the `request_id` field. The attacker-controlled value is then interpolated directly into a filesystem path: ```python result_file = RESULT_DIR / f"{request_id}.json" ``` A `request_id` containing traversal components such as `../../...` can cause the resolved output path to escape `RESULT_DIR`. More importantly, if `request_id` is an absolute path, Python's `pathlib` discards the preceding `RESULT_DIR` component when joining the paths. The resulting file is opened in write mode, which creates the file if it does not exist and truncates it if it does. The implementation also does not reject symbolic links, use exclusiv ...[truncated 1467 chars]- Remediation
View remediation
