Skip to content

UntrustedInclusion ​

error off by default

Group: Security · PhpStorm name: UntrustedInclusionInspection

Including a file by a relative path makes PHP search include_path (and the current working directory), so a different file than intended can be loaded. Anchor paths with __DIR__ (or rely on autoloading).

Example ​

php
<?php
require_once 'lib/boot.php';
include ("views/header.phtml");
$cfg = require('settings.php');

function plugin()
{
    $entry = 'plugins/main.php';
    include_once $entry;
}

require __DIR__ . '/lib/boot.php';
include '/srv/app/shared.php';
require 'D:/apps/shared.php';
include $dynamic;
include '';
include 'phar://app.phar/boot.php';
include '\\\\fileserver\\shared\\boot.php';

Reported:

  • line 2: Relative include depends on include_path; anchor it with __DIR__.
  • line 3: Relative include depends on include_path; anchor it with __DIR__.
  • line 4: Relative include depends on include_path; anchor it with __DIR__.
  • line 9: Relative include depends on include_path; anchor it with __DIR__.

Configure ​

In custos.json:

json
{
  "rules": {
    "UntrustedInclusion": {
      "enabled": true
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore UntrustedInclusion

/**
 * @noinspection UntrustedInclusionInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.