T09 · Insecure Skill Coding Practices
- Location
scripts/md2pptx.py:40- Finding
Predictable Intermediate HTML File Allows Arbitrary Writable-File Overwrite
- Content
View full analysis
Vulnerability Details
File Location:
scripts/md2pptx.py, lines 40–43
Vulnerability Type: Predictable temporary file and symlink-following file overwrite
Risk Level: MediumVulnerable Code
python # Save intermediate HTML html_file = input_path.with_suffix('.html') with open(html_file, 'w', encoding='utf-8') as f: f.write(html_content)The related cleanup operation occurs at line 58:
python html_file.unlink() # Clean up HTMLTechnical Analysis
The intermediate HTML pathname is deterministically derived from the input pathname. For example, converting
presentation.mdcauses the script to write topresentation.htmlin the same directory.Opening this predictable path with mode
wsilently truncates any existing file. It also follows symbolic links. Therefore, if an attacker can create files in the input directory, the attacker can createpresentation.htmlas a symbolic link to another file writable by the user running the converter. The script then follows that link and replaces the target's contents with generated HTML.On successful LibreOffice conversion,
unlink()removes the intermediate pathname. If it was a symbolic link, this removes only the link after the linked target has already been corrupted. The implementation also lacks exclusive file creation, symlink checks, restrictive temporary-file permissions, and guaranteed cleanup through afinallyblock.Attack Path
- The attacker obtains write access to a directory from which the victim will convert a Markdown file.
- The attacker predicts the intermediate name from the input name. For
presentation.md, the intermediate path ispresentation.html. - The attacker creates
presentation.htmlas a symbolic link to a sensitive file that the victim can write. - The victim runs
md2pptx.py presentation.md. - The
open(..., 'w')operation follows the symbolic link and truncates the target.
...[truncated 984 chars]
- Remediation
View remediation
Remediation Suggestions
-
Create intermediate files with Python's
tempfilemodule instead of deriving their names from user-controlled input:python import tempfile output_dir = Path(output_file).parent output_dir.mkdir(parents=True, exist_ok=True) with tempfile.TemporaryDirectory(prefix="md2pptx-") as temp_dir: html_file = Path(temp_dir) / "input.html" html_file.write_text(html_content, encoding="utf-8") # Run the converter and copy or move the validated result afterward. -
Use an isolated temporary directory with restrictive permissions, and let its context manager guarantee cleanup on success, timeout, conversion failure, or unexpected exception.
-
Never overwrite a sibling file merely because it has the same stem as the Markdown input.
-
If a fixed destination must be used, create it atomically and exclusively, reject symbolic links, and verify that the resolved path remains inside the intended directory.
-
Create the output directory explicitly and validate the generated file before moving it to the requested destination.
-
Handle output replacement deliberately using a documented overwrite policy and an atomic move, rather than relying on
rename()behavior.
-
