From 454fdcdfc310049f0726cc5ab9faadbe422b795d Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Sun, 31 May 2026 17:53:59 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[CRITICAL/H?= =?UTF-8?q?IGH]=20Fix=20path=20traversal?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: bashandbone <89049923+bashandbone@users.noreply.github.com> --- .jules/sentinel.md | 4 ++++ .../flow/src/incremental/extractors/typescript.rs | 14 +++++++++++++- 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 .jules/sentinel.md diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 00000000..28444e13 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2026-05-31 - [Path Traversal in Manual Path Resolution] +**Vulnerability:** The manual path resolution logic in the TypeScript extractor popped path components directly when encountering `Component::ParentDir`. This could allow traversal escapes if paths like `../../foo` were evaluated, as the `ParentDir` components were erroneously dropped when the components stack was empty. +**Learning:** Rust's `PathBuf::canonicalize()` resolves `..`, but when dealing with unresolved paths (e.g., inside non-existent directories), manual component traversal must handle `ParentDir` correctly. Specifically, dropping `ParentDir` without checking if the base of the path is already relative can truncate directory traversal semantics inappropriately. +**Prevention:** When manually resolving paths with `std::path::Component`, explicitly block `Component::ParentDir` from popping `Component::RootDir` or `Component::Prefix`. Furthermore, if the current component list is empty or its last element is already `Component::ParentDir`, append the `Component::ParentDir` instead of ignoring it. diff --git a/crates/flow/src/incremental/extractors/typescript.rs b/crates/flow/src/incremental/extractors/typescript.rs index 1bdda4ef..bf9ecf9f 100644 --- a/crates/flow/src/incremental/extractors/typescript.rs +++ b/crates/flow/src/incremental/extractors/typescript.rs @@ -808,7 +808,19 @@ impl TypeScriptDependencyExtractor { for component in resolved.components() { match component { std::path::Component::ParentDir => { - components.pop(); + let last = components.last(); + match last { + Some(std::path::Component::RootDir) + | Some(std::path::Component::Prefix(_)) => { + // Do not pop RootDir or Prefix to prevent traversal escapes + } + Some(std::path::Component::ParentDir) | None => { + components.push(component); + } + _ => { + components.pop(); + } + } } std::path::Component::CurDir => {} _ => components.push(component),