fix: validate image name before building registry path #4

Merged
marvin merged 1 commits from fix/registry-path-validation into master 2026-08-26 22:18:43 +02:00
1 Commits
Author SHA1 Message Date
marvin 5b80885207 fix: validate image name before building registry path
CI / build (pull_request) Successful in 10s
CI / build (push) Successful in 10s
The user-supplied image/name argument was interpolated unsanitized into
registry/{name}/initrd, so a name containing '../' (e.g. 'slim run
../../.ssh/authorized_keys') escaped the XDG data dir and let slim
create directories and read/write files at attacker-chosen locations.

validate_image_name now rejects empty names, '.', '..' and anything
outside [A-Za-z0-9._:-] at the registry_dir chokepoint used by both
build and run, plus a defense-in-depth containment check that the
resolved path stays under the registry root.

Fixes sec-2 from the code review.
2026-08-26 20:11:57 +00:00