AOSSIE-Org / AOSSIE-Org/PictoPy

BUG: Path traversal vulnerability in face search endpoint allows reading files outside image directories

Abierto
#1,322 3 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Python
Estrellas
283
Forks
679
Merge medio
7 d 2 h
PR fusionados (30 d)
3

Descripción

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

## Is there an existing issue for this?
I have searched the existing issues and this has not been reported.

## Describe the bug
In `backend/app/routes/face_clusters.py` lines 221-242, the file
path received from the request payload is used directly in
`os.path.isfile()` and `open()` without any boundary validation.

## Code
```python
file_path = request.body.get("image_path")
if os.path.isfile(file_path):
with open(file_path, "rb") as f:
data = f.read()
```

## Problem
A path like `../../Documents/private.pdf` or
`../../AppData/Roaming/com.pictopy.app/settings.json`
would pass the `os.path.isfile()` check and allow reading
files outside the intended image directories.

## Impact
- Read files outside designated image folders
- Access PictoPy's own database and settings files
- Access user's personal documents
- Low risk currently (desktop-only) but becomes critical
if network/sharing features are added in future

## Expected Behavior
The backend should validate that the provided path stays
within the registered image directories before processing.

## Proposed Fix
```python
base_dir = os.path.abspath(ALLOWED_IMAGES_DIR)
requested = os.path.abspath(file_path)
if not requested.startswith(base_dir):
raise HTTPException(
status_code=400,
detail="Invalid file path"
)
```

## Classification
- Type: Path Traversal / Directory Traversal
- CWE: CWE-22
- Severity: Low (desktop-only, local access required)

## Steps to Reproduce
1. Start PictoPy backend
2. Send POST request to face search endpoint with
image_path set to a path traversal payload
3. Observe that files outside image directories are accessible

## Environment
- OS: Windows/Linux/macOS
- PictoPy version: 1.1.0

### Record

- [x] I agree to follow this project's Code of Conduct

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.