Store: reject path traversal in the store index's "file" field

entry.file comes from the remote store catalog (index.json) and is
joined onto DIRECTORY_GAME verbatim in OnLaunchClick() - Path::operator/
does plain string concatenation with no ".." normalization. On
platforms/builds where the index isn't fetched over HTTPS
(SYSPROP_SUPPORTS_HTTPS false), a network MITM or a compromised store
backend could use a crafted "file" value to make "Launch" boot an
arbitrary host file path instead of the selected store item. Reuse the
existing HasParentDirComponent() helper to reject such entries.
This commit is contained in:
Henrik Rydgård committed 2026-08-12 09:27:47 +02:00
1 parent 7f7fe3c712
commit e35764d8e0
1 file changed
+7
+7
View File
@@ -34,6 +34,7 @@
#include "Core/Config.h"
#include "Core/System.h"
#include "Core/Util/GameManager.h"
#include "Core/Util/PathUtil.h"
#include "UI/EmuScreen.h"
#include "UI/Store.h"
@@ -498,6 +499,12 @@ void StoreScreen::ParseListing(const std::string &json) {
const char *file = game.getStringOr("file", nullptr);
if (!file)
continue;
// entry_.file gets joined onto DIRECTORY_GAME verbatim in OnLaunchClick()
// (Path::operator/ does no ".." normalization); on platforms/builds where
// the store index isn't fetched over HTTPS, a MITM'd or compromised
// response could otherwise point "launch" at an arbitrary host path.
if (HasParentDirComponent(file))
continue;
e.file = file;
entries_.push_back(e);
}