fix: validate IDs in GetNextCheckpointSequence before directory read · Entire

fix: validate IDs in GetNextCheckpointSequence before directory read

5811c2b→main·

Soph·1mo ago·1 file·+7 added/-0 removed

The PostToolUse (TodoWrite) hook passed input.SessionID and the task tool-use ID straight into SessionMetadataDirFromSessionID / TaskMetadataDir and then os.ReadDir, with no validation — unlike every other hook entry point. A crafted "../.." could redirect the directory listing. Validate both IDs at this choke point; an invalid value simply starts the checkpoint sequence at 1.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com

Sessions

ddf2fe4a50feView transcript

Changes

1

637 unmodified lines

638
639
640
641
642
643
644
645
646
647
648
649
650

637 unmodified lines

// It counts existing checkpoint files in the task metadata checkpoints directory.
// Returns 1 if no checkpoints exist yet.
func GetNextCheckpointSequence(sessionID, taskToolUseID string) int {
    // sessionID/taskToolUseID arrive from agent hook input and are used as path
    // components below. Reject unsafe values so a crafted "../.." cannot redirect
    // the os.ReadDir to an arbitrary directory; an invalid ID just starts at 1.
    if validation.ValidateSessionID(sessionID) != nil || validation.ValidateToolUseID(taskToolUseID) != nil {
        return 1
    }

// Use the session ID directly as the metadata directory name
    sessionMetadataDir := paths.SessionMetadataDirFromSessionID(sessionID)
taskMetadataDir := strategy.TaskMetadataDir(sessionMetadataDir, taskToolUseID)

Mcmd/entire/cli/state.go+7