Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

🔒 Missing workspace boundary validation allows arbitrary file read

Aperta
#3,265 11 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
78/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
security

Direzione di ricerca

Start in rust/crates/runtime/src/file_ops.rs at read_file, then inspect normalize_path and validate_workspace_boundary. Verify that the resolved path is checked against workspace_root before reading, including traversal and symlink escape cases; the issue is done when out-of-workspace reads are rejected while valid workspace reads still work.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

🔒 Security · 🟡 Medium · Confidence: 96%

File: rust/crates/runtime/src/file_ops.rs
Location: read_file


What's wrong

The function reads a file path supplied by the caller without checking that it stays inside the intended workspace. The line let absolute_path = normalize_path(path)?; resolves the user‑provided path to an absolute path, but no subsequent call to validate_workspace_boundary is made, so a malicious caller can traverse out of the workspace (e.g., using ../ or symlinks) and read any file the process can access.

Suggested fix

Validate the resolved path against the workspace root before reading the file. For example:

pub fn read_file(
    path: &str,
    offset: Option<usize>,
    limit: Option<usize>,
    workspace_root: &Path,
) -> io::Result<ReadFileOutput> {
    let absolute_path = normalize_path(path)?;
    // Ensure the path stays within the workspace
    validate_workspace_boundary(&absolute_path, workspace_root)?;
    // ... rest of the function unchanged ...
}

About this report

This finding was generated by an automated audit tool using Llama 3.3 70B + verification passes.
Only findings with ≥92% confidence that passed both LLM self-verification and line reference
verification are reported. False positives are still possible — please verify before acting.

Lingua principale
Rust
Stelle
195k
Fork
108k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di ultraworkers/claw-code

Tutte le issue di ultraworkers/claw-code

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.