Skip to content

fix(security): detect Windows drive letters and reserved device names in isArchiveEntryNameSafe #919

Description

@ZhuchkaTriplesix

Summary

In isArchiveEntryNameSafe (lib/core/security/archive_path_guard.dart, lines 13–18):

bool isArchiveEntryNameSafe(String entryName) {
  if (entryName.contains('..')) return false;
  if (entryName.startsWith('/') || entryName.startsWith('\\')) return false;
  return true;
}

This check is used across archive extractors in local_extension_installer.dart, http_marketplace_repository.dart, and update_install_utils.dart to prevent Zip Slip / path traversal attacks.

However, the validation only checks for leading / and \:

  1. Windows Drive Letters: Paths with drive letters such as C:\Windows\System32\payload.dll or D:file.exe do not start with a slash and do not contain ... When passed to p.join(root, entryName) on Windows, absolute drive paths override the destination directory root.
  2. Windows Reserved Device Names: Entries named CON, PRN, AUX, NUL, COM1-9, or LPT1-9 (and variants with extensions like CON.txt) cause file lockups or system I/O errors on Windows.
  3. Null Bytes: Entry names containing embedded null bytes (\0) can lead to filesystem truncation vulnerabilities on POSIX and Windows.

Repro

  1. Create a zip archive containing an entry named C:\test.txt or CON.
  2. Run isArchiveEntryNameSafe(entry.name).
  3. Observe it returns true.

Scope

  • Reject entry names containing Windows drive letters (^[a-zA-Z]:).
  • Reject Windows reserved device names (CON, PRN, AUX, NUL, COM1-9, LPT1-9).
  • Reject entry names containing null bytes or control characters.
  • Add unit tests verifying malicious Windows archive entry paths are safely blocked.

Out of scope

  • Archive password decryption.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't workingcoreCore library logic and servicesmarketplaceExtensions marketplace, ExtensionManifest

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions