Skip to content

fix: prevent path traversal in /files download endpoint [FaaFyfxR9WAQrL7FcAgEHJvztd8cVMxvjHRS55rw1nwH] - #11244

Open
waterWang wants to merge 1 commit into
PaddlePaddle:developfrom
waterWang:develop
Open

waterWang wants to merge 1 commit into
PaddlePaddle:developfrom
waterWang:develop

Conversation

@waterWang

Copy link
Copy Markdown

Summary

Fix a path traversal vulnerability in the /files download endpoint (slm/pipelines/rest_api/controller/file_upload.py).

Vulnerability

os.path.join(FILE_PARSE_PATH, file_name) discards the base directory when file_name is an absolute path (e.g. /etc/passwd). An unauthenticated remote attacker can read any file readable by the server process.

Fix

Use os.path.basename(file_name) to strip all directory components before joining with FILE_PARSE_PATH.

PoC

# Before fix: reads arbitrary files
curl http://target:8000/files?file_name=/etc/passwd

# After fix: only returns files within FILE_PARSE_PATH
curl http://target:8000/files?file_name=/etc/passwd  # returns 404

Closes #11236

os.path.join discards the base directory when the user-supplied
file_name is an absolute path (e.g. /etc/passwd), allowing an
unauthenticated remote attacker to read arbitrary files readable
by the server process.

Fix: use os.path.basename() to strip all directory components
before joining with FILE_PARSE_PATH.

Closes PaddlePaddle#11236
@paddle-bot

paddle-bot Bot commented Jul 26, 2026

Copy link
Copy Markdown

Thanks for your contribution!

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 60 days with no activity. 当前Pull Request 60天内无活动,被标记为stale。

@github-actions github-actions Bot added the stale label Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: PaddleNLP /files Endpoint Arbitrary File Read via Absolute Path Override

2 participants