Skip to content

fix(security): resolve file reader and summarizer path injection sinks - #29

Merged
spelech merged 1 commit into
mainfrom
fix/codeql-remove-sinks-file-reader-summarizer
Sep 27, 2026
Merged

spelech merged 1 commit into
mainfrom
fix/codeql-remove-sinks-file-reader-summarizer

Conversation

@spelech

@spelech spelech commented Sep 27, 2026

Copy link
Copy Markdown
Owner

Summary

  • Summarize Endpoint: Pre-validate payload.path through FileReaderService.resolve_safe_path in app/api/routers/files.py prior to passing to SummarizerService, preventing arbitrary path traversal via POST /admin/api/files/summarize.
  • File Reader Guards: Standardize candidate.startswith(root) and cand_storage.startswith(storage_root) direct prefix barriers, validating path containment without disjunctions and removing meaningless os.path.sep checks in read_file and is_binary_file.
  • Symlink & Storage Containment: Validate realpath containment and prevent traversal prior to returning resolved paths.

Verification

  • All 524 backend unit and integration tests passing (pytest).

if norm_fp and os.path.exists(norm_fp) and os.path.isfile(norm_fp):
try:
norm_fp = os.path.normpath(os.path.abspath(filepath))
if os.path.exists(norm_fp) and os.path.isfile(norm_fp):
if norm_fp and os.path.exists(norm_fp) and os.path.isfile(norm_fp):
try:
norm_fp = os.path.normpath(os.path.abspath(filepath))
if os.path.exists(norm_fp) and os.path.isfile(norm_fp):
@spelech
spelech merged commit de27482 into main Sep 27, 2026
14 of 15 checks passed
@spelech
spelech deleted the fix/codeql-remove-sinks-file-reader-summarizer branch September 27, 2026 11:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants