T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/tracker.py:98- Finding
Directory Traversal Through Unvalidated Stock Code in Tracking Filename
- Content
View full analysis
7 else "", source="cli" ) ``` ### Technical Analysis The stock code is embedded directly into a filename. No allowlist, regular expression, path normalization, or containment check prevents the value from containing path separators or `..` traversal components. `os.path.join(TRACKING_DIR, filename)` only combines paths; it does not guarantee that the resulting normalized path remains inside `TRACKING_DIR`. An input containing traversal sequences can therefore cause the file operation to escape the intended tracking directory. The date and generated identifier suffix prevent reliable selection of an exact final filename, but they do not prevent creation of an attacker-influenced JSON filename in another writable directory. Exploitation is limited by the operating-system privileges of the process and requires any referenced intermediate directories to exist. ### Attack Path 1. An attacker obtains the ability to invoke the local tracking CLI or otherwise call `record_recommendation()` with controlled input. 2. The attacker supplies a stock code containing traversal components, such as a value beginning with `../../`. 3. The CLI passes the value through `sys.argv[2]` ...[truncated 1084 chars]- Remediation
View remediation
