T09 · Insecure Skill Coding Practices
- Location
scripts/swmm_calibrate.py:470- Finding
Path Traversal Through Unvalidated Trial Names
- Content
View full analysis
- Remediation
View remediation
str: if not isinstance(name, str) or not SAFE_TRIAL_NAME.fullmatch(name): raise ValueError( "Trial name may contain only letters, digits, underscores, and hyphens" ) return name ``` 2. Explicitly reject empty values, absolute paths, path separators, `.` and `..`. Apply the validation uniformly to candidate JSON names and `--trial-name`. 3. Add a containment check as a defense-in-depth measure before any directory creation or file write: ```python root = run_root.resolve() safe_name = validate_trial_name(trial["name"]) trial_dir = (root / safe_name).resolve() if not trial_dir.is_relative_to(root): raise ValueError("Trial directory escapes the configured run root") ``` For Python versions without `Path.is_relative_to()`, use `relative_to()` inside a `try` block and reject `ValueError`. 4. Reject duplicate trial names before processing a batch so one candidate cannot overwrite another candidate's artifacts. 5. Where feasible, create each trial directory with a trusted generated identifier and retain the user-provided name only as metadata. 6. Run calibration under a dedicated, unprivileged account with write access restricted to the configured run directory. 7. Add regression tests covering `../target`, `../../target`, absolute paths, platform-specific separators, empty names, duplicate names, and valid identifiers. ]]>
