AOSSIE-Org / AOSSIE-Org/PictoPy

BUG: Path traversal vulnerability in face search endpoint allows reading files outside image directories

未关闭
#1,322 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
283
派生
679
平均合并
7 天 2 小时
30 天内合并 PR
3

描述

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

## Is there an existing issue for this?
I have searched the existing issues and this has not been reported.

## Describe the bug
In `backend/app/routes/face_clusters.py` lines 221-242, the file
path received from the request payload is used directly in
`os.path.isfile()` and `open()` without any boundary validation.

## Code
```python
file_path = request.body.get("image_path")
if os.path.isfile(file_path):
with open(file_path, "rb") as f:
data = f.read()
```

## Problem
A path like `../../Documents/private.pdf` or
`../../AppData/Roaming/com.pictopy.app/settings.json`
would pass the `os.path.isfile()` check and allow reading
files outside the intended image directories.

## Impact
- Read files outside designated image folders
- Access PictoPy's own database and settings files
- Access user's personal documents
- Low risk currently (desktop-only) but becomes critical
if network/sharing features are added in future

## Expected Behavior
The backend should validate that the provided path stays
within the registered image directories before processing.

## Proposed Fix
```python
base_dir = os.path.abspath(ALLOWED_IMAGES_DIR)
requested = os.path.abspath(file_path)
if not requested.startswith(base_dir):
raise HTTPException(
status_code=400,
detail="Invalid file path"
)
```

## Classification
- Type: Path Traversal / Directory Traversal
- CWE: CWE-22
- Severity: Low (desktop-only, local access required)

## Steps to Reproduce
1. Start PictoPy backend
2. Send POST request to face search endpoint with
image_path set to a path traversal payload
3. Observe that files outside image directories are accessible

## Environment
- OS: Windows/Linux/macOS
- PictoPy version: 1.1.0

### Record

- [x] I agree to follow this project's Code of Conduct

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。