fix(llm-security): F-2/F-3 — contain path traversal + kill npm-view shell injection

Session B of the security-fix track. Both sinks trusted untrusted strings at a
filesystem/subprocess boundary; same fix family as F-1.

F-2 (HIGH, arbitrary file write) — scanners/auto-cleaner.mjs: applyFixes() did
resolve(targetPath, f.file) with no containment, then wrote the cleaned content
back. f.file is untrusted (scanned-repo filenames, or a fully attacker-chosen
--findings file), so file: "../../.claude/settings.json" let the cleaner modify
files OUTSIDE the scanned tree. Add a prefix-containment check before grouping:
absPath must equal targetPath or start with targetPath + sep, else the finding
is refused and reported as skipped. (Documented residual gap: prefix containment
does not stop a symlink inside the tree pointing out — noted inline.)

F-3 (HIGH, command injection, pre-confirmation) — hooks/scripts/
pre-install-supply-chain.mjs: inspectNpmPackage ran execSafe(`npm view ${spec}
--json`), a shell string. spec derives from package tokens parsed out of the
scanned Bash command, so a metachar-bearing token reached the shell on
PreToolUse(Bash) — BEFORE the install, so it ran even if the user then denied
the command. Switch to spawnSync('npm', ['view', spec, '--json']) (no shell);
spec is passed as one argv element. The static `npm audit --json` execSafe call
is left as-is (no interpolation).

TDD (repro -> red -> green):
- tests/scanners/auto-cleaner-traversal.test.mjs: a "../secret.txt" finding must
  not rewrite the outside file; contained files still get cleaned.
- tests/hooks/supply-chain-injection.test.mjs: `npm install $(>/abs/PWNED)`
  (redirect-only $(...) survives normalizeBashExpansion + the whitespace split)
  must not create the sentinel.

Closing gates: full node --test suite 1863/0 (was 1860; +3); gitleaks clean;
F-1 regression re-run GREEN (sink still closed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3s6WnubSSrFjAQTLQdVbG
This commit is contained in:
Kjell Tore Guttormsen 2026-06-20 11:09:13 +02:00
commit 3f64aa5bab
4 changed files with 180 additions and 2 deletions

View file

@ -20,6 +20,7 @@
// - Allow (exit 0): everything else
import { readFileSync, existsSync } from 'node:fs';
import { spawnSync } from 'node:child_process';
import {
AGE_THRESHOLD_HOURS,
NPM_COMPROMISED, PIP_COMPROMISED, CARGO_COMPROMISED, GEM_COMPROMISED,
@ -251,7 +252,15 @@ function checkNpmProvenance(meta) {
function inspectNpmPackage(name, version) {
const spec = version ? `${name}@${version}` : name;
const raw = execSafe(`npm view ${spec} --json`);
// F-3: `spec` derives from attacker-controlled package tokens parsed out of the
// scanned Bash command. Pass it as a discrete argv element via spawnSync (no
// shell), so metacharacters like ';', '$(...)', backticks are never interpreted.
// npm still receives the full spec and reports the metadata (or an error JSON on
// stdout for an invalid name), matching the previous execSafe behaviour.
const res = spawnSync('npm', ['view', spec, '--json'], {
timeout: 10000, encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'],
});
const raw = res.stdout || null;
if (!raw) return null;
try { return JSON.parse(raw); } catch { return null; }
}