🔒 Missing workspace boundary validation allows arbitrary file read
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 78/100
Línea de trabajo
Start in rust/crates/runtime/src/file_ops.rs at read_file, then inspect normalize_path and validate_workspace_boundary. Verify that the resolved path is checked against workspace_root before reading, including traversal and symlink escape cases; the issue is done when out-of-workspace reads are rejected while valid workspace reads still work.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
🔒 Security · 🟡 Medium · Confidence: 96%
File: rust/crates/runtime/src/file_ops.rs
Location: read_file
What's wrong
The function reads a file path supplied by the caller without checking that it stays inside the intended workspace. The line let absolute_path = normalize_path(path)?; resolves the user‑provided path to an absolute path, but no subsequent call to validate_workspace_boundary is made, so a malicious caller can traverse out of the workspace (e.g., using ../ or symlinks) and read any file the process can access.
Suggested fix
Validate the resolved path against the workspace root before reading the file. For example:
pub fn read_file(
path: &str,
offset: Option<usize>,
limit: Option<usize>,
workspace_root: &Path,
) -> io::Result<ReadFileOutput> {
let absolute_path = normalize_path(path)?;
// Ensure the path stays within the workspace
validate_workspace_boundary(&absolute_path, workspace_root)?;
// ... rest of the function unchanged ...
}
About this report
This finding was generated by an automated audit tool using Llama 3.3 70B + verification passes.
Only findings with ≥92% confidence that passed both LLM self-verification and line reference
verification are reported. False positives are still possible — please verify before acting.
- Lenguaje dominante
- Rust
- Estrellas
- 195k
- Forks
- 108k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ultraworkers/claw-code
-
Fix markdown formatting issues in TUI streaming: block-level element newline omission and consecutive empty line accumulationQuizá libre de nuevo @Aditaya08 la tomó hace 49 días y no hay ningún pull request abierto. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
ultraworkers/claw-code#3259 · 7 comentarios ·
-
fix(cli): resolve duplicate assistant text printing after 'Done' in non-compact text modePosiblemente ocupada @nankingjing la tomó hace 88 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
ultraworkers/claw-code#3258 · 1 comentario ·
-
bug: Missing newlines before paragraphs and code blocks in streamed Markdown renderingPosiblemente ocupada @nankingjing la tomó hace 89 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
ultraworkers/claw-code#3257 · 2 comentarios ·
-
[CRITICAL][SECURITY] Untrusted project hooks bypass read-only mode for arbitrary command executionAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 68/100
ultraworkers/claw-code#3301 · 4 comentarios ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 20/100
ultraworkers/claw-code#3300 · 2 comentarios ·
Todos los issues de ultraworkers/claw-code
Issues similares
-
app enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 80/100
elodin-sys/elodin#890 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
guidance-ai/llguidance#391 ·
-
documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
Verifiedz/Shimmer#144 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
点击设置提示`操作未能完成,详情请查看应用日志`Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Y-ASLant/ElegantClipboard#166 ·