Skip to content

🔒 fix: prevent path traversal on input file read - #128

Merged
akutuva21 merged 1 commit into
masterfrom
fix-path-traversal-input-10377525129266671774
Jun 2, 2026
Merged

akutuva21 merged 1 commit into
masterfrom
fix-path-traversal-input-10377525129266671774

Conversation

@akutuva21

Copy link
Copy Markdown
Owner

🎯 What: Fixed a path traversal vulnerability in scripts/apply-gallery-assignments.js where the user-provided input argument was not validated before being passed to fs.readFile.
⚠️ Risk: If left unfixed, an attacker could potentially exploit this to read arbitrary files from the system executing the script by supplying a payload like --input ../../../../etc/passwd.
🛡️ Solution: Used the existing safeJoin utility function imported from ./utils.js to securely combine the current working directory (process.cwd()) and the user-provided input. safeJoin natively validates that the resolved path does not traverse outside the intended base directory, throwing a Path traversal security risk detected error if traversal is attempted.


PR created automatically by Jules for task 10377525129266671774 started by @akutuva21

Fixes a critical security vulnerability where the `input` argument
to `scripts/apply-gallery-assignments.js` was passed directly to
`fs.promises.readFile()`, allowing for arbitrary file read via
path traversal (e.g. `../../../../etc/passwd`).

The `input` is now sanitized using the `safeJoin` utility function,
which validates that the resulting path remains within the base
directory (`process.cwd()`) and throws an explicit error if a path
traversal attempt is detected.

Co-authored-by: akutuva21 <44119804+akutuva21@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@akutuva21
akutuva21 marked this pull request as ready for review June 2, 2026 14:58
@akutuva21
akutuva21 merged commit ceb558f into master Jun 2, 2026
1 check passed
@akutuva21
akutuva21 deleted the fix-path-traversal-input-10377525129266671774 branch June 2, 2026 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant