馃悰 fix(discovery): skip empty PATH entries - #132
Merged
Merged
Conversation
get_paths() turned every PATH entry into a Path via map(Path, ...) with
no filtering. An empty entry - a leading, trailing, or doubled
separator - means "current directory" per POSIX and Windows PATH
semantics, so Path("") resolved to it and the caller's cwd got
searched for interpreters alongside every real directory on PATH.
Confirmed on a real machine: PATH=/usr/bin:/bin: with a
python3.11-named file planted in an attacker-writable cwd got that
file executed during discovery's own interrogation step, independent
of whether it was ultimately selected as the result.
filter(None, ...) drops the empty entries before they become Path
objects.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
get_paths()turned everyPATHentry into aPathwith no filtering. An empty entry (leading, trailing, or doubled separator) means "current directory" on both POSIX and Windows, soPath("")resolved to it and the caller's cwd got searched for interpreters alongside every realPATHdirectory.I confirmed this on a real machine. With
PATH=/usr/bin:/bin:and apython3.11-named file planted in an attacker-writable cwd, discovery's own interrogation step executed that file, whether or not it went on to pick it as the result.filter(None, ...)drops empty entries before they becomePathobjects.Tracked as GHSA-f7q5-7cq5-gvgh.