Repository navigation
[security] directory traversal in tempfile prefix #79459
Description
Activity
YusukeEndoh commented
on Nov 19, 2018 YusukeEndohmannequinMannequinAuthorMore actionsHello,
The tempfile library does not check the prefix argument, which can be exploited to create files outside tmpdir by using directory traversal.
>>> import tempfile >>> tempfile.gettempprefix() 'tmp' >>> f = tempfile.NamedTemporaryFile(prefix="/home/mame/cracked") >>> f.name '/home/mame/crackedlt3y_ddm'The same issue was found and treated as a vulnerability in PHP (CVE-2006-1494) and Ruby (CVE-2018-6914).
I first reported this issue to security@python.org at July 2018. Some people kindly discussed it, and finally I was told to create a ticket here.
- added3.8 (EOL)end of lifeend of lifestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
on Nov 19, 2018 Ruby handled this issue as a vulnerability:
https://www.ruby-lang.org/en/news/2018/03/28/unintentional-file-and-directory-creation-with-directory-traversal-cve-2018-6914/The doc of "gettempprefix" says "This does not contain the directory component", so it is natural for users to think "prefix" will accept only a file name.
Maybe we can silently truncated the directort part of the prefix to only keep the base name in stable branches, but raise an exception in Python 3.8? Or maybe emit a deprecation warning in Python 3.7?
- changed the title
[-]directory traversal in tempfile prefix[/-][+][security] directory traversal in tempfile prefix[/+]on Nov 19, 2018 Hello,
I have created patch and MR for the Python 3.8 "exception" approach.For the reference here is patch for ruby:
ruby/ruby@e9ddf2bMaybe we should consider also validation on suffix as in their solution?
Adding Łukasz to the nosy list as release manager.
I am not sure if this justifies a new issue so I add this here.
The suffix parameter can also be used for a traversal attack. It is possible to completely clobber anything in dir and prefix (at least on Windows).
e.g. calling mkdtemp or NamedTemporaryFile with these paramers ...
dir=r"C:\tmp", prefix="pre", suffix="../../../../../../../../../gotcha"
Will result in a directory or file being created at C:/gotcha.
I also wonder if this would justify adding a warning to the documentation for all existing Python versions?
Quoting from the documentation of mkstemp (https://docs.python.org/3/library/tempfile.html#tempfile.mkstemp):
If prefix is specified, the file name will begin with that prefix; otherwise, a default prefix is used.
If dir is specified, the file will be created in that directory [...]
As both claims are rendered untrue when using suffix in the above described way I think this should be amended.
I found this issue after helping someone solve a Stack Overflow question at https://stackoverflow.com/q/58767241/100297; they eventually figured out that their prefix was a path, not a path element.
I'd be all in favour of making tempfile._sanitize_params either reject a prefix or suffix with
os.seporos.altsepcharacters, or just take the last element of os.path.split().- added3.7 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life
on Mar 14, 2021 Is the problem planned to be solved? I found no reply for a long time.
So far, nobody proposed a pull request to fix the issue.
- added3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixesand removed3.7 (EOL)end of lifeend of life
on Mar 2, 2024 - added a commit that references this issue
on Oct 5, 2026 tempfile now fails with ValueError in this case. I close the issue.
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs
prefixandsuffixparameters totempfilefunctions. #143889ValueErrorif theprefixorsuffixcontains a directory component. #150477