AOSSIE-Org / AOSSIE-Org/PictoPy

BUG: Path traversal vulnerability in face search endpoint allows reading files outside image directories

未關閉
#1,322 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
283
分支
679
平均合併
7 天 2 小時
30 天內合併 PR
3

描述

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

## Is there an existing issue for this?
I have searched the existing issues and this has not been reported.

## Describe the bug
In `backend/app/routes/face_clusters.py` lines 221-242, the file
path received from the request payload is used directly in
`os.path.isfile()` and `open()` without any boundary validation.

## Code
```python
file_path = request.body.get("image_path")
if os.path.isfile(file_path):
with open(file_path, "rb") as f:
data = f.read()
```

## Problem
A path like `../../Documents/private.pdf` or
`../../AppData/Roaming/com.pictopy.app/settings.json`
would pass the `os.path.isfile()` check and allow reading
files outside the intended image directories.

## Impact
- Read files outside designated image folders
- Access PictoPy's own database and settings files
- Access user's personal documents
- Low risk currently (desktop-only) but becomes critical
if network/sharing features are added in future

## Expected Behavior
The backend should validate that the provided path stays
within the registered image directories before processing.

## Proposed Fix
```python
base_dir = os.path.abspath(ALLOWED_IMAGES_DIR)
requested = os.path.abspath(file_path)
if not requested.startswith(base_dir):
raise HTTPException(
status_code=400,
detail="Invalid file path"
)
```

## Classification
- Type: Path Traversal / Directory Traversal
- CWE: CWE-22
- Severity: Low (desktop-only, local access required)

## Steps to Reproduce
1. Start PictoPy backend
2. Send POST request to face search endpoint with
image_path set to a path traversal payload
3. Observe that files outside image directories are accessible

## Environment
- OS: Windows/Linux/macOS
- PictoPy version: 1.1.0

### Record

- [x] I agree to follow this project's Code of Conduct

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。