Skip to content

fix(portability): refuse path traversal in import_into - #15

Merged
faj-design5260 merged 2 commits into
tigerless-labs:mainfrom
egarlian:fix/import-path-traversal-guard
Sep 23, 2026
Merged

faj-design5260 merged 2 commits into
tigerless-labs:mainfrom
egarlian:fix/import-path-traversal-guard

Conversation

@egarlian

@egarlian egarlian commented Sep 5, 2026

Copy link
Copy Markdown
Contributor
  • import_into builds the target path as store.root / entry["path"]
    and writes to it without checking that the resolved path stays under
    the store root.
  • An export payload carrying ../../etc/malicious or an absolute path
    like /tmp/escape would write outside the store directory. The
    export path cannot produce such entries (relative_to constrains
    them), but import_into is a public function that any caller can
    reach with an arbitrary payload.

Fix: resolve the target path and verify it is relative to the
resolved store root before writing. Refuse with a ValueError if the
path escapes.

target = (store.root / str(entry[KEY_PATH])).resolve()
if not target.is_relative_to(store.root.resolve()):
    raise ValueError(f"path traversal refused: {entry[KEY_PATH]}")

Files changed:

  • packages/core/src/agent_memory/core/portability.py — 2-line guard
    in import_into
  • tests/unit/test_portability.py — 5 tests: round-trip, file export,
    ../ traversal refusal, absolute path refusal, valid relative path
$ python3 -m pytest tests/unit/test_portability.py -v
5 passed in 0.97s

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants