T09 · Insecure Skill Coding Practices
- Location
server.py:289- Finding
Caller-Controlled Queue Path Allows Arbitrary File Creation, Overwrite, and Deletion
- Content
View full analysis
= len(queue_data.get("contacts", [])): queue_data = { "contacts": contacts, "message": message, "current_index": 0 } ``` ### Technical Analysis The public `dingding_send_batch` tool accepts a caller-supplied `queue_file` path and passes it directly to file-reading, writing, and deletion operations. The code performs no canonicalization, directory confinement, ownership validation, symbolic-link protection, or regular-file validation. Consequently, an MCP ca ...[truncated 1850 chars]- Remediation
View remediation
