T09 · Insecure Skill Coding Practices
- Location
scripts/build-uni.js:23- Finding
Unrestricted Private-Key Path Allows Arbitrary File Overwrite
- Content
View full analysis
"$KEY_PATH" chmod 400 "$KEY_PATH" echo " 私钥已写入: $KEY_PATH" ``` ### Technical Analysis Both publishing scripts accept `WEAPP_PRIVATE_KEY_PATH` directly from the environment and use it as a filesystem destination without validating or confining it to the project workspace. The Node.js implementation creates missing parent directories recursively and then calls `fs.writeFileSync`, which truncates an existing file by default. The shell implementation similarly creates the parent directory and overwrites the selected file through shell redirection. Absolute paths and traversal paths such as `../../target-file` are not rejected. Consequently, anyone able to influence the environment of the publishing process can overwrite any file writable by the account running the CI job or local script. ### Attack Path 1. An attacker compromises a CI variable, modifies an unprotected pipeline configuration, or otherwise controls the environment used to invoke the publishing script. 2. The attacker sets `WEAPP_PRIVATE_KEY_PATH` to a sensitive writable location, such as a workspace configuration file or a user-owned startup/co ...[truncated 1075 chars]- Remediation
View remediation
