T09 · Insecure Skill Coding Practices
- Location
tool.py:41- Finding
Terminal Escape-Sequence Injection Through Untrusted Log Content
- Content
View full analysis
Vulnerability Details
File Location:
tool.py, lines 41–49 and 86
Vulnerability Type: Improper neutralization of terminal control sequences
Risk Level: MediumVulnerable Code
python def format_line(line: str) -> str: # Colorize timestamps for pattern in TIMESTAMP_PATTERNS: line = pattern.sub(colorize_timestamp, line) # Colorize log levels line = LEVEL_PATTERN.sub(colorize_level, line) return linepython formatted = format_line(line.rstrip('\n')) print(formatted)Technical Analysis
The program treats log lines as untrusted input but writes them directly to the terminal after only applying regular-expression substitutions for timestamps and log levels. It does not remove, encode, or otherwise neutralize preexisting terminal control characters.
Consequently, ANSI CSI sequences, OSC sequences, and other terminal control codes embedded in a malicious log entry remain intact and are interpreted by the user's terminal. The highlighting codes intentionally added by the application do not protect against attacker-supplied control sequences.
Attack Path
- An attacker causes an application or service to record a crafted string containing terminal escape sequences.
- The crafted content is stored in a log file or reaches a log stream processed by this tool.
- A user opens or follows that log using
tool.py. format_line()preserves the attacker's escape sequences.print(formatted)sends those sequences to the terminal.- The terminal interprets them, potentially rewriting displayed content, hiding security-relevant log entries, altering terminal state, or activating terminal-specific OSC features.
Impact Assessment
Exploitation occurs with the privileges and capabilities of the terminal emulator used by the person reviewing the log. It does not directly grant shell execution or elevated operating-system privileges in the audited code.
A successful attack can falsify ...[truncated 290 chars]
- Remediation
View remediation
Remediation Suggestions
Sanitize every untrusted log line before adding application-controlled highlighting:
- Remove or visibly encode ANSI CSI, OSC, DCS, APC, PM, and related escape sequences.
- Remove or escape unsafe C0 and C1 control characters while explicitly allowing only required formatting characters, such as tabs.
- Apply trusted color highlighting only after sanitization.
- Consider rendering control characters in a visible form, such as
\x1b, so analysts can inspect malicious content safely. - If raw terminal controls are required, expose them only through an explicit, clearly documented opt-in option.
- Add regression tests using CSI cursor movement, screen-clearing sequences, OSC title changes, OSC clipboard payloads, carriage returns, backspaces, and malformed or truncated escape sequences.
- Prefer a well-tested terminal-sanitization implementation rather than an incomplete regular expression that handles only a subset of escape syntax.
