Repository navigation
Conversation
The CleanupPathCommand accepts user-provided paths via CLI arguments and passes them directly to the deleteAsync function from the 'del' library without validation or sanitization
viceice
left a comment
There was a problem hiding this comment.
this works as intended. you can't elevate your permissions. so you can also simply run rm /etc/passwd, so it's not a vulnerabillity heer
|
Thanks for the review; agreed on the threat-model point. I was treating the path traversal as a CWE-22 issue without sufficiently accounting for the fact that cleanup-path is a local CLI operation and the caller already has the filesystem permissions of the process. In that context, supplying ../../../... doesn’t provide a privilege escalation or meaningful additional capability, so I agree that the HIGH severity/security-vulnerability classification isn’t justified. I’ll withdraw the vulnerability claim rather than trying to force the change through as a security fix. The path validation could still be considered as defence-in-depth if restricting cleanup to a particular root is a desired product invariant, but I understand that’s a behavioral/design decision rather than a security vulnerability in the current threat model. |
Summary
Address high severity security finding in
src/cli/command/cleanup-path.ts.Vulnerability
V-001src/cli/command/cleanup-path.ts:24Description: The CleanupPathCommand accepts user-provided paths via CLI arguments and passes them directly to the deleteAsync function from the 'del' library without validation or sanitization. Paths are split by ':' character and flattened before being passed to deleteAsync. An attacker can provide path traversal sequences (e.g., '../../../etc/passwd') to delete files outside the intended directory.
Evidence
Exploitation scenario: An attacker invokes the CLI tool with malicious path arguments containing traversal sequences: 'containerbase-cli cleanup path "../../../etc/passwd"' or 'containerbase-cli cleanup path.
Scanner confirmation: multi_agent_ai rule
V-001flagged this pattern.Production code: This file is in the production codebase, not test-only code.
Threat Model Context
This is a private Node.js application (not published to npm). Vulnerabilities affect this application's own runtime only.
Changes
src/cli/command/cleanup-path.tsBehavior Preservation
The change is scoped to 1 file on the vulnerable path.
Security Invariant
Regression test
This test guards against regressions — it's useful independent of the code change above.
This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.
Automated security fix by OrbisAI Security