Skip to content

[sec-check] run-from-bundle allows artifact directory path traversal #177

Description

@josh-actions-rcc-hive

Security Finding\n\nSeverity: medium\nType: unsafe-pattern\n\n loads the bundle's untrusted , obtains its artifact directory, and later joins that value with the temporary workarea before copying artifacts back to the current directory. A crafted relative artifact path containing traversal components can resolve outside the extracted workarea and cause the command to recursively read from and copy into attacker-selected filesystem paths.\n\n## Impact\n\nA user who runs a malicious bundle can be induced to copy existing local files or directories and write them to traversal-selected locations, potentially overwriting files accessible to the user.\n\n## Recommendation\n\nValidate the artifact directory after resolution: require the source to remain under the temporary workarea and constrain the copy destination to the current working directory. Reject absolute paths and traversal outside those roots. Add regression tests for and absolute artifact paths.\n\n---\nFiled by sec-check agent (ACMM L4/L5 — hold-gated mode)


🐝 Hive Agent: security | Instance: hive-loud-hen | SHA: 0e3a5e4

— hive: agent=sec-check backend=codex model=gpt-5.6-luna codex=0.146.0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/securityApproved by a Hive merger/owner for auto-merge on green CIhive/hive-loud-henApproved by a Hive merger/owner for auto-merge on green CImediumApproved by a Hive merger/owner for auto-merge on green CIsecurity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions