{"record":{"id":"15529cb52399a281","repo":"ruvnet/ruflo","slug":"namespace-contains-path-traversal","errorCode":null,"errorMessage":"namespace contains path traversal","messagePattern":"namespace contains path traversal","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/mcp-tools/memory-tools.ts","lineNumber":805,"sourceCode":"    description: 'Enumerate stored memory entries (optionally filtered by namespace/tags) without semantic search. Use when native Glob is wrong because the entries are not files (they live in .swarm/memory.db). For inspection / audit / \"what is in my memory\" — pair with memory_search for retrieval-by-meaning.',\n    category: 'memory',\n    inputSchema: {\n      type: 'object',\n      properties: {\n        namespace: { type: 'string', description: 'Filter by namespace' },\n        limit: { type: 'number', description: 'Maximum results (default: 50)' },\n        offset: { type: 'number', description: 'Offset for pagination (default: 0)' },\n      },\n    },\n    handler: async (input) => {\n      await ensureInitialized();\n      const { listEntries } = await getMemoryFunctions();\n\n      const namespace = input.namespace as string | undefined;\n      const limit = (input.limit as number) || 50;\n      const offset = (input.offset as number) || 0;\n\n      if (namespace) { const vNs = validateIdentifier(namespace, 'namespace'); if (!vNs.valid) throw new Error(vNs.error); }\n\n      try {\n        const result = await listEntries({\n          namespace,\n          limit,\n          offset,\n        });\n\n        const entries = result.entries.map(e => ({\n          key: e.key,\n          namespace: e.namespace,\n          storedAt: e.createdAt,\n          updatedAt: e.updatedAt,\n          accessCount: e.accessCount,\n          hasEmbedding: e.hasEmbedding,\n          size: e.size,\n        }));\n","sourceCodeStart":787,"sourceCodeEnd":823,"githubUrl":"https://github.com/ruvnet/ruflo/blob/9c61c86f06b439af2a95085ae9bb0ca839662e41/v3/@claude-flow/cli/src/mcp-tools/memory-tools.ts#L787-L823","documentation":"validateIdentifier's PATH_TRAVERSAL check (/\\.\\.[/\\\\]/) fires before the charset check, so a namespace containing ../ or ..\\ anywhere fails memory_list with 'namespace contains path traversal' (memory-tools.ts:705). This blocks attempts to escape the namespace's storage directory in file-backed memory layouts. A namespace like 'a..b' (dots without a following slash/backslash) is fine; 'a/../b' is not.","triggerScenarios":"memory_list with namespace 'data/../prod', 'a\\\\..\\\\b' (Windows-style), or any user-supplied value in which '..' is immediately followed by / or \\.","commonSituations":"Joining namespace segments with '../' shortcuts when composing paths; passing unvalidated user input as a namespace; security-test payloads probing for traversal.","solutions":["Remove '..' segments — use flat names ('prod', 'data-prod') instead of relative path walks","Normalize first: namespace.replace(/\\.\\.[/\\\\]/g, '_')","If namespaces need hierarchy, use ':' or '-' as the separator (allowed by the charset rule), never '/'","Reject '../' in your input layer before the value ever reaches the tool"],"exampleFix":"// before\nawait mcp.callTool('memory_list', { namespace: 'data/../prod' }); // namespace contains path traversal\n\n// after\nawait mcp.callTool('memory_list', { namespace: 'data:prod' });","handlingStrategy":"validation","validationCode":"function denyTraversal(ns: string): string | null {\n  if (/\\.\\.[/\\\\]/.test(ns)) return null; // reject\n  return ns;\n}\nconst safeNs = denyTraversal(rawNs) ?? rawNs.split('/').filter(Boolean).join(':');","typeGuard":"function containsPathTraversal(ns: string): boolean {\n  return /\\.\\.[/\\\\]/.test(ns);\n}\n// if (containsPathTraversal(ns)) throw new Error('namespace must not contain ../ or ..\\\\');","tryCatchPattern":"try {\n  await memoryList({ namespace: ns });\n} catch (e) {\n  if (e instanceof Error && e.message.includes('namespace contains path traversal')) {\n    // security rejection — never 'fix' automatically beyond stripping ../; prefer rejecting the input\n  }\n  throw e;\n}","preventionTips":["Never compose namespaces from relative path joins; use flat or ':'-separated names","Treat traversal hits as hostile input: log and reject rather than silently rewrite","Use ':' or '-' as hierarchy separators — '/' is not allowed by the charset rule anyway","Fuzz-test namespace-receiving endpoints with '../' payloads to confirm your pre-validation fires"],"tags":["memory","mcp","list","security","path-traversal","namespace"],"backgroundTag":"path-traversal-blocked","analyzedSha":"9c61c86f06b439af2a95085ae9bb0ca839662e41","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}