[Security] nano-banana-pro follows output symlinks and overwrites files outside the working directory
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 88/100
Línea de trabajo
Comienza en skills/nano-banana-pro/scripts/generate_image.py, donde el argumento --filename se convierte en la ruta de salida antes de escribir la imagen. Compara ese destino resuelto (os.path.realpath) con el directorio de trabajo y omítelo o recházalo cuando el destino sea un symlink o se salga de él; la corrección sugerida en el issue también menciona un flag explícito de sobrescritura para destinos existentes. Verifica con los pasos de reproducción: crea el symlink en un espacio de trabajo temporal, ejecuta el script y confirma que el archivo centinela fuera del espacio de trabajo permanece sin cambios. Se considera terminado cuando el caso del symlink se rechaza con un error claro, mientras que los nombres de archivo de salida normales siguen funcionando.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Hi, I found a symlink-following issue in the nano-banana-pro skill that can overwrite files outside the working directory.
GitHub: https://github.com/steipete/agent-scripts/tree/main/skills/nano-banana-pro
ClawHub: https://clawhub.ai/steipete/skills/nano-banana-pro
Summary
generate_image.py saves the generated image to the path supplied with --filename without rejecting symlinks or checking that the resolved path stays inside the working directory.
If an untrusted repository contains result.png as a symlink to a file outside the repository, running the skill from that repository with --filename result.png follows the link and overwrites the target with PNG data. This can corrupt or destroy files that the OpenClaw process can write.
Steps to reproduce
-
Create an isolated test directory:
mkdir -p /tmp/nbp-test/workspace /tmp/nbp-test/outside printf 'SAFE TEST SENTINEL\n' > /tmp/nbp-test/outside/victim.txt ln -s ../outside/victim.txt /tmp/nbp-test/workspace/result.png -
From the workspace, run the skill with a valid Gemini API key available through
GEMINI_API_KEY:cd /tmp/nbp-test/workspace python3 /path/to/nano-banana-pro/scripts/generate_image.py \ --prompt "A simple blue square on a plain light background." \ --filename result.png -
Check the target:
file /tmp/nbp-test/outside/victim.txt
Expected behavior
The script should reject symlink outputs and any resolved output path outside the working directory.
Actual behavior
The script follows result.png and writes the generated PNG to /tmp/nbp-test/outside/victim.txt.
Impact
An attacker who can provide or modify repository contents can place the output symlink in the repository. If a user or agent runs image generation from that repository using the symlink name, files outside the repository may be overwritten or corrupted, subject to the OpenClaw process's file permissions.
Affected versions
Confirmed in nano-banana-pro 1.0.0 and 1.0.1.
Suggested fix
Reject symlink outputs and verify the resolved destination remains within the intended output directory before writing. Consider requiring an explicit overwrite option when the destination already exists.
- Lenguaje dominante
- Shell
- Estrellas
- 7.2k
- Forks
- 617
- Merge medio
- 6 d 18 h
- PR fusionados (30 d)
- 2
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
aws-samples/appmod-blueprints#972 ·
Los mantenedores suelen responder en 1 día
-
[Bug]: remote-ls --updates reports up-to-date OCI refs because it ignores deployed Alt-idPosiblemente ocupada @Joao-kouznetz la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
status:needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 3 días