Skip to content

[Aikido] Fix path traversal bypass in normalized filepath comparison logic - #440

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137952334-65sb
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137952334-65sb

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a path traversal vulnerability in the path traversal scanner where attackers could bypass detection by providing exact dangerous directory paths. The vulnerability existed because the scanner was comparing raw user input against dangerous directory prefixes instead of comparing normalized filepaths. The fix normalizes both the resolved filepath and user input before comparison, ensuring consistent path validation. Changes were made to lib/aikido/zen/scanners/path_traversal/helpers.rb and corresponding test cases in test/aikido/zen/scanners/path_traversal_scanner_test.rb to properly detect path traversal attempts.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811805687
HIGH
PathTraversal::Helpers.start_with_unsafe_path? returns false when the raw payload equals a configured dangerous directory, without requiring the final normalized filepath to equal that directory. For a payload of /etc and a constructed filepath of /etc/passwd, the filepath is recognized as being beneath the dangerous prefix but line 74 takes the exact-prefix exemption. An application endpoint that combines this request-controlled directory with a trusted filename can therefore access a sensitive descendant despite the firewall's blocking mode. The one-character early return for / is a separate residual bypass and should be tracked independently rather than treated as necessary to establish this finding.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant