Skip to content

πŸ›‘οΈ Sentinel: [CRITICAL] Fix Path Traversal Bypass#21

Merged
LebToki merged 1 commit intomainfrom
sentinel-path-traversal-bypass-13539185397145297378
Mar 21, 2026
Merged

πŸ›‘οΈ Sentinel: [CRITICAL] Fix Path Traversal Bypass#21
LebToki merged 1 commit intomainfrom
sentinel-path-traversal-bypass-13539185397145297378

Conversation

@LebToki
Copy link
Owner

@LebToki LebToki commented Mar 21, 2026

🚨 Severity: CRITICAL
πŸ’‘ Vulnerability: Path traversal / Authorization Bypass where a user could access sibling directories by creating a directory sharing the same prefix as an allowed directory (e.g., /var/www_backup when /var/www is allowed).
🎯 Impact: Attackers could gain unauthorized access to read, create, delete, or rename files and directories outside of their allowed workspaces or system folders, compromising the security of the host system.
πŸ”§ Fix: Modified the path validation logic across the API endpoints to strictly enforce directory boundaries by appending a trailing slash (/) to the allowed directory path before performing the prefix check using strpos. Also added exact match checks for the root of the allowed directory.
βœ… Verification: Ran php tests/SecurityTest.php and manually verified with test scripts that unauthorized path bypasses are now correctly rejected.


PR created automatically by Jules for task 13539185397145297378 started by @LebToki

Fix a path traversal bypass vulnerability in `public/api/files.php`, `public/api/terminal.php`, `public/api/projects.php`, and `src/Utils/Security.php` where validating if a user-supplied path is within an allowed directory using `strpos($realPath, $allowedReal) === 0` allowed access to sibling directories (e.g., an allowed path `/var/www` matched the malicious path `/var/www_backup`). Fixed by ensuring exact path matches or appending a trailing directory separator (`/`) to the allowed path prefix.
@google-labs-jules
Copy link

πŸ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a πŸ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@codemaker-ai-app
Copy link

Hello from @codemakerai.

CodeMaker AI GitHub App integration.

Usage:

@codemakerai [command or prompt]

Assistant

All Assistant features are supported in GitHub. Assistant can answer general questions as well as questions directly
related to code. It also has code editing capabilities.

@codemakerai assistant prompt - the assistant prompt
@codemakerai prompt - the assistant prompt. Alias to assistant command.

Commands

Pull Request Commands - commands that can be posted as comments on the pull request:

@codemakerai help - prints this help message
@codemakerai review process - process the most recent code review and all it's comments
@codemakerai generate code [codepath] - generate code for all files in pull request, or only for matching code path.
@codemakerai generate docs [codepath] - generate documentation for all files in pull request, or only for matching code path.
@codemakerai replace code [codepath] - replace code for all files in pull request, or only for matching code path.
@codemakerai replace docs [codepath] - replace documentation for all files in pull request, or only for matching code path.
@codemakerai fix syntax - fixes the syntax in all files
@codemakerai commit undo - removes the most recent commit

Pull Request Code Review Commands - commands that can be posted as comments on the code review i.e. "Files changed" tab:

@codemakerai assistant prompt - the assistant prompt
@codemakerai explain - explains the code
@codemakerai review - reviews the code

Triggers

To automatically trigger certain actions on pull requests you can create and use the following GitHub labels.

codemakerai-pull-request-generate-documentation - automatically generates comments/documentation on Pull Request creation.
codemakerai-pull-request-syntax-autocorrection - automatically corrects syntax on Pull Request creation.
codemakerai-pull-request-review-process - automatically processes code review comments on Pull Request Review submission.

For in depth explanation of the features, please consult https://docs.codemaker.ai

In case of any issues please report them to https://community.codemaker.ai

@LebToki LebToki marked this pull request as ready for review March 21, 2026 15:24
@LebToki LebToki merged commit 0dd498d into main Mar 21, 2026
1 check passed
@LebToki LebToki deleted the sentinel-path-traversal-bypass-13539185397145297378 branch March 21, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant