mirror of
https://github.com/gopasspw/gopass.git
synced 2026-10-10 19:49:01 +02:00
safePath only performed a lexical prefix check, so a symlink inside the store whose target lives outside the root passed validation. Get, Set, Delete, Prune, Move, Link, LinkTarget, Exists and IsDir then acted on the real target outside the store. List already resolved symlinks and skipped escapes; that protection was missing from the read, write and delete paths. Resolve the longest existing prefix of the requested path and verify the real location stays within the store root. Walking up to the longest existing prefix catches symlinked entries and intermediate directory symlinks while still allowing paths whose trailing components do not exist yet, e.g. when creating a new secret. Fixes GHSA-v4c2-4fvx-chr3. Signed-off-by: Dominik Schulz <dominik.schulz@gauner.org>