T09 · Insecure Skill Coding Practices
- Location
scripts/publish_html.py:64- Finding
Arbitrary Local File Read and External Upload Through HTML Image References
- Content
View full analysis
]+src=["\']([^"\']+)["\']' def replace_image(match): src = match.group(1) if 'mmbiz.qpic.cn' in src or 'wx.qlogo.cn' in src: return match.group(0) if not src.startswith(('http://', 'https://', '/')): src = os.path.join(html_dir, src) print(f"[UPLOAD] Upload image: {src}") media_id, new_url = self.upload_image(src) if new_url: return match.group(0).replace(match.group(1), new_url) else: print(f"[WARN] Image upload failed, preserving original URL: {src}") return match.group(0) ``` ### Technical Analysis The publisher treats every `src` attribute in an HTML `` element as a trusted image location. Absolute paths are accepted directly, while relative paths are joined to the HTML file's directory without canonicalization or an allowed-directory check. The resulting path is opened with the process's current filesystem privileges. The code performs no validation that: - The canonical path remains under the article's asset directory. - The path does not contain traversal sequences. - The target is a regular file rather than a special file or symbolic link. - The bytes represent a supported image. - The file has an acceptable size. - The operator explicitly authoriz ...[truncated 1962 chars]
- Remediation
View remediation
