Skip to content

fix: export file deletion path validation#41008

Open
SamJUK wants to merge 2 commits into
magento:2.4-developfrom
SamJUK:fix/importexport-export-delete-traversal
Open

fix: export file deletion path validation#41008
SamJUK wants to merge 2 commits into
magento:2.4-developfrom
SamJUK:fix/importexport-export-delete-traversal

Conversation

@SamJUK

@SamJUK SamJUK commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

Summary

Restrict the Import/Export export-file deletion action to completed export files within var/export.

This brings the delete action in line with the sibling export-file download action, which already canonicalizes the requested filename and permits only valid export files beneath var/export

The action now follows the same validation pattern as the sibling download endpoint:

  • Canonicalizes the requested filename.
  • Requires the resolved file to exist under var/export.
  • Accepts only configured export-file extensions.
  • Deletes using the validated relative export path.

Scope

This is intentionally a narrow Import/Export filesystem-boundary hardening change.

The existing filesystem directory abstraction already prevents paths from escaping Magento’s var/ directory. Before this change, a relative filename could still resolve outside the intended var/export directory and target another file within var/.

After this change, the delete action is limited to valid completed export artifacts in var/export. It does not change access control, affect paths outside this Import/Export workflow, or alter normal export-file deletion behaviour.

Test coverage

Adds an integration test confirming that a traversal-style filename cannot delete a CSV located outside var/export.

Contribution checklist (*)

  • Pull request has a meaningful description of its purpose
  • All commits are accompanied by meaningful commit messages
  • All new or changed code is covered with unit/integration tests (if applicable)
  • README.md files for modified modules are updated and included in the pull request if any README.md predefined sections require an update
  • All automated tests passed successfully (all builds are green)

@m2-assistant

m2-assistant Bot commented Jul 18, 2026

Copy link
Copy Markdown

Hi @SamJUK. Thank you for your contribution!
Here are some useful tips on how you can test your changes using Magento test environment.
❗ Automated tests can be triggered manually with an appropriate comment:

  • @magento run all tests - run or re-run all required tests against the PR changes
  • @magento run <test-build(s)> - run or re-run specific test build(s)
    For example: @magento run Unit Tests

<test-build(s)> is a comma-separated list of build names.

Allowed build names are:
  1. Database Compare
  2. Functional Tests CE
  3. Functional Tests EE
  4. Functional Tests B2B
  5. Integration Tests
  6. Magento Health Index
  7. Sample Data Tests CE
  8. Sample Data Tests EE
  9. Sample Data Tests B2B
  10. Static Tests
  11. Unit Tests
  12. WebAPI Tests
  13. Semantic Version Checker

You can find more information about the builds here
ℹ️ Run only required test builds during development. Run all test builds before sending your pull request for review.


For more details, review the Code Contributions documentation.
Join Magento Community Engineering Slack and ask your questions in #github channel.

@ct-prd-pr-scan

Copy link
Copy Markdown

The security team has been informed about this pull request due to the presence of risky security keywords. For security vulnerability reports, please visit Adobe's vulnerability disclosure program on HackerOne or email psirt@adobe.com.

@SamJUK

SamJUK commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

@magento run all tests

@SamJUK

SamJUK commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

@magento run Static Tests

@SamJUK

SamJUK commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

@magento run all tests

@SamJUK
SamJUK force-pushed the fix/importexport-export-delete-traversal branch from 3f48ff2 to e510b7d Compare July 18, 2026 21:16
@SamJUK

SamJUK commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

@magento run all tests

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant