EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Description
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, EnvironmentManager.restore(env, backupId) computes the backup path with join(envDir, '.backups', backupId) and only checks that this path exists. It does not resolve the result or verify that it remains under data//.backups. A caller can pass a traversal backup ID such as ../../../outside/source-dir to restore files from an arbitrary directory into the target environment data directory. The issue is fixed in v5.12.2. restore() now validates backupId against /^[\w\-]+$/ and asserts dirname(resolve(join(backupsDir, backupId))) === resolve(backupsDir) before touching the filesystem. Backup IDs containing path separators or .. are rejected, so a crafted ID can no longer copy directories from outside .backups/ into the environment.
Affected products
2- Range: <5.12.2
- Range: <5.12.2
Patches
Vulnerability mechanics
References
3- github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3mitrex_refsource_MISC
- github.com/Jovancoding/Network-AI/releases/tag/v5.12.2mitrex_refsource_MISC
- github.com/Jovancoding/Network-AI/security/advisories/GHSA-48x2-6pr9-2jjfmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.