# fix: validate IDs in GetNextCheckpointSequence before directory read

`5811c2b`→[main](/content/gh/entireio/cli/commits/main/index.html)·

Soph·1mo ago·1 file·+7 added/-0 removed

The PostToolUse (TodoWrite) hook passed input.SessionID and the task
tool-use ID straight into SessionMetadataDirFromSessionID /
TaskMetadataDir and then os.ReadDir, with no validation — unlike every
other hook entry point. A crafted "../.." could redirect the directory
listing. Validate both IDs at this choke point; an invalid value simply
starts the checkpoint sequence at 1.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

## Sessions

ddf2fe4a50feView transcript

## Changes

1

- cmd/entire/cli

- Mstate.go+7

```
637 unmodified lines

638
639
640
641
642
643
644
645
646
647
648
649
650

637 unmodified lines

// It counts existing checkpoint files in the task metadata checkpoints directory.
// Returns 1 if no checkpoints exist yet.
func GetNextCheckpointSequence(sessionID, taskToolUseID string) int {
	// sessionID/taskToolUseID arrive from agent hook input and are used as path
	// components below. Reject unsafe values so a crafted "../.." cannot redirect
	// the os.ReadDir to an arbitrary directory; an invalid ID just starts at 1.
	if validation.ValidateSessionID(sessionID) != nil || validation.ValidateToolUseID(taskToolUseID) != nil {
		return 1
	}

// Use the session ID directly as the metadata directory name
	sessionMetadataDir := paths.SessionMetadataDirFromSessionID(sessionID)
taskMetadataDir := strategy.TaskMetadataDir(sessionMetadataDir, taskToolUseID)
```

Mcmd/entire/cli/state.go+7
