T09 · Insecure Skill Coding Practices
- Location
scripts/download_file.py:23- Finding
Remote Drive Filename Can Escape the Destination Directory and Overwrite Local Files
- Content
View full analysis
None: # Get filename if dest_path is a directory if os.path.isdir(dest_path): meta = ( drive.files() .get(fileId=file_id, fields="name", supportsAllDrives=True) .execute() ) dest_path = os.path.join(dest_path, meta["name"]) request = drive.files().get_media(fileId=file_id, supportsAllDrives=True) with open(dest_path, "wb") as fh: downloader = MediaIoBaseDownload(fh, request) done = False while not done: status, done = downloader.next_chunk() pct = int(status.progress() * 100) print(f"\rDownloading... {pct}%", end="", flush=True) print(f"\nSaved to: {dest_path}") ``` ### Technical Analysis When the destination supplied through `--dest` is a directory, the script retrieves the file name from Google Drive metadata and passes it directly to `os.path.join`. The resulting path is then opened in `wb` mode without normalization, containment validation, or overwrite protection. The Drive filename is remote data and must therefore be treated as untrusted. A name containing path traversal components can cause the resolved destination to escape the selected download directory. On platforms where an attacker-controlled name is interpreted as an absolute path, `os.path.join` can also discard the intended directory entirely. Opening the resulting path with `open(dest_path, "wb")` creates a new file or truncates an existing file. The script does not check whether the target already exists, whether it is a symbolic link, or whether its resolved path remains under the requested directory. ### Attack Path 1. An attacker creates or controls a Google Drive fil ...[truncated 1558 chars]- Remediation
View remediation
