Skip to content

[Aikido] Fix path-traversal bypass via terminal ".." component detection - #443

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137952979-8iyf
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137952979-8iyf

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a path-traversal vulnerability where terminal ".." components could bypass detection when normalized by path functions like File.join. The fix enhances unsafe path detection logic in lib/aikido/zen/context.rb and lib/aikido/zen/scanners/path_traversal/helpers.rb to identify standalone ".." components and paths ending with "/.." or ".." before path normalization occurs. Comprehensive test coverage has been added to test/aikido/zen/context_test.rb, test/aikido/zen/scanners/path_traversal_scanner_test.rb, and test/aikido/zen/sinks/file_test.rb to validate detection of this bypass scenario.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811805533
HIGH
This is a real enforcement bypass in the in-scope firewall-ruby path-traversal protection. Scalar request values are retained as their original payload strings. When a consuming application performs a composition such as File.join(base_dir, params[:dir], "secret"), a request value of .. produces a path containing ../secret, while the associated payload remains exactly ... PathTraversalScanner#attack? requires include_unsafe_path_parts? to be true for both the composed filepath and the original input. Because DANGEROUS_PATH_PARTS contains ../ and ..\\ but not a terminal .. component, the input check fails; the relative input also does not satisfy the separate absolute-path check. Blocking mode consequently does not raise an attack exception, and the protected filesystem operation proceeds with the escaped path. The concrete impact is path traversal to files reachable by the process, including unauthorized reads or mutations where the consuming application exposes a c

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant