Skip to content

Security: Path traversal in received file — no sanitization of filename from metadata #2

Description

@daschinmoy21

Severity: High

In the TCP receiver (tcp.rs) and QUIC receiver (quic.rs), the filename field from FileMetadata is used directly to construct the output file path with no sanitization. A malicious sender could set filename to ../../.bashrc or similar and overwrite arbitrary files on the receiver machine.

Affected Files

  • src/protocol/tcp.rs — receiver writes to format!("tcp_rec_{}", meta.filename)
  • src/protocol/quic.rs line 143 — format!("quic_rec_{}", meta.filename)
  • src/transfer/metadata.rs — filename is just the raw path from sender: filename: path.into()

Suggested Fix

fn sanitize_filename(filename: &str) -> String {
    std::path::Path::new(filename)
        .file_name()
        .and_then(|n| n.to_str())
        .unwrap_or("received_file")
        .to_string()
}

Use the sanitized filename (basename only, no directory components) for all received files. Never trust sender-provided paths.


Issue filed by Hermes — automated code audit

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    highHigh severitysecuritySecurity vulnerability

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions