🔒 Missing workspace boundary validation allows arbitrary file read
まだ誰も着手していません。
評価
調査の方向性
Start in rust/crates/runtime/src/file_ops.rs at read_file, then inspect normalize_path and validate_workspace_boundary. Verify that the resolved path is checked against workspace_root before reading, including traversal and symlink escape cases; the issue is done when out-of-workspace reads are rejected while valid workspace reads still work.
索引モデルが issue の本文から書いたものです。
説明
🔒 Security · 🟡 Medium · Confidence: 96%
File: rust/crates/runtime/src/file_ops.rs
Location: read_file
What's wrong
The function reads a file path supplied by the caller without checking that it stays inside the intended workspace. The line let absolute_path = normalize_path(path)?; resolves the user‑provided path to an absolute path, but no subsequent call to validate_workspace_boundary is made, so a malicious caller can traverse out of the workspace (e.g., using ../ or symlinks) and read any file the process can access.
Suggested fix
Validate the resolved path against the workspace root before reading the file. For example:
pub fn read_file(
path: &str,
offset: Option<usize>,
limit: Option<usize>,
workspace_root: &Path,
) -> io::Result<ReadFileOutput> {
let absolute_path = normalize_path(path)?;
// Ensure the path stays within the workspace
validate_workspace_boundary(&absolute_path, workspace_root)?;
// ... rest of the function unchanged ...
}
About this report
This finding was generated by an automated audit tool using Llama 3.3 70B + verification passes.
Only findings with ≥92% confidence that passed both LLM self-verification and line reference
verification are reported. False positives are still possible — please verify before acting.
- 主要言語
- Rust
- スター
- 195k
- フォーク
- 108k
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ultraworkers/claw-code のほかの issue
-
Fix markdown formatting issues in TUI streaming: block-level element newline omission and consecutive empty line accumulation再び着手できるかも @Aditaya08 が 50 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
ultraworkers/claw-code#3259 · コメント 7 件 ·
-
fix(cli): resolve duplicate assistant text printing after 'Done' in non-compact text mode対応中かも @nankingjing が 89 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
ultraworkers/claw-code#3258 · コメント 1 件 ·
-
bug: Missing newlines before paragraphs and code blocks in streamed Markdown rendering対応中かも @nankingjing が 89 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
ultraworkers/claw-code#3257 · コメント 2 件 ·
-
[CRITICAL][SECURITY] Untrusted project hooks bypass read-only mode for arbitrary command executionオープン
難易度 4/5 3〜5日 初心者へのやさしさ 68/100
ultraworkers/claw-code#3301 · コメント 4 件 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 20/100
ultraworkers/claw-code#3300 · コメント 2 件 ·
ultraworkers/claw-code の issue をすべて見る
似ている issue
-
mxl-compile: пример заполнения ячеек отклоняется Unica対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープン
難易度 1/5 1〜3時間 初心者へのやさしさ 91/100
IngvarConsulting/unica#1301 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 75/100
ajeetraina/awesome-docker-sbx#220 ·
-
`helios / deploy`: switch zone wait in `deploy.sh` has almost no headroom over healthy startup times対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンTest Flake
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
oxidecomputer/omicron#11453 ·
メンテナーはふだん 1 日以内に返信