Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Security] nano-banana-pro follows output symlinks and overwrites files outside the working directory

Abierto Apto para principiantes
#46 1 comentario 1 reacción 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
88/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
python
Área
security

Línea de trabajo

Comienza en skills/nano-banana-pro/scripts/generate_image.py, donde el argumento --filename se convierte en la ruta de salida antes de escribir la imagen. Compara ese destino resuelto (os.path.realpath) con el directorio de trabajo y omítelo o recházalo cuando el destino sea un symlink o se salga de él; la corrección sugerida en el issue también menciona un flag explícito de sobrescritura para destinos existentes. Verifica con los pasos de reproducción: crea el symlink en un espacio de trabajo temporal, ejecuta el script y confirma que el archivo centinela fuera del espacio de trabajo permanece sin cambios. Se considera terminado cuando el caso del symlink se rechaza con un error claro, mientras que los nombres de archivo de salida normales siguen funcionando.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

clawsweeper:needs-security-review clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:data-loss impact:security issue-rating: 🦞 diamond lobster P2

Hi, I found a symlink-following issue in the nano-banana-pro skill that can overwrite files outside the working directory.
GitHub: https://github.com/steipete/agent-scripts/tree/main/skills/nano-banana-pro
ClawHub: https://clawhub.ai/steipete/skills/nano-banana-pro

Summary

generate_image.py saves the generated image to the path supplied with --filename without rejecting symlinks or checking that the resolved path stays inside the working directory.

If an untrusted repository contains result.png as a symlink to a file outside the repository, running the skill from that repository with --filename result.png follows the link and overwrites the target with PNG data. This can corrupt or destroy files that the OpenClaw process can write.

Steps to reproduce

  1. Create an isolated test directory:

    mkdir -p /tmp/nbp-test/workspace /tmp/nbp-test/outside
    printf 'SAFE TEST SENTINEL\n' > /tmp/nbp-test/outside/victim.txt
    ln -s ../outside/victim.txt /tmp/nbp-test/workspace/result.png
    
  2. From the workspace, run the skill with a valid Gemini API key available through GEMINI_API_KEY:

    cd /tmp/nbp-test/workspace
    python3 /path/to/nano-banana-pro/scripts/generate_image.py \
      --prompt "A simple blue square on a plain light background." \
      --filename result.png
    
  3. Check the target:

    file /tmp/nbp-test/outside/victim.txt
    

Expected behavior

The script should reject symlink outputs and any resolved output path outside the working directory.

Actual behavior

The script follows result.png and writes the generated PNG to /tmp/nbp-test/outside/victim.txt.

Impact

An attacker who can provide or modify repository contents can place the output symlink in the repository. If a user or agent runs image generation from that repository using the symlink name, files outside the repository may be overwritten or corrupted, subject to the OpenClaw process's file permissions.

Affected versions

Confirmed in nano-banana-pro 1.0.0 and 1.0.1.

Suggested fix

Reject symlink outputs and verify the resolved destination remains within the intended output directory before writing. Consider requiring an explicit overwrite option when the destination already exists.

Lenguaje dominante
Shell
Estrellas
7.2k
Forks
617
Merge medio
6 d 18 h
PR fusionados (30 d)
2

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.