T09 · Insecure Skill Coding Practices
- Location
api/browser/open-url.js:29- Finding
Shell Command Injection in the URL Opener
- Content
View full analysis
{ console.log(`✅ Opened: ${process.argv[2]}`); process.exit(0) }) .catch(err => { console.error(`❌ ${err.message}`); process.exit(1) }) } module.exports = { openUrl } ``` ### Technical Analysis The URL is interpolated into a command string passed to `child_process.exec`. Unlike argument-based process APIs, `exec` invokes an operating-system shell. A URL containing quotation marks and shell metacharacters can terminate the intended quoted argument and append another shell command. The `isAllowedUrl` check verifies that the protocol is HTTPS and that the parsed hostname belongs to `i.beautsgo.com`. That validation prevents arbitrary destinations, but it does not make the complete URL safe for shell interpretation. Shell metacharacters can occur outside the parsed hostname, such as in the path, query string, or fragment. Current calls from `api/skill.js` use static hospital URLs, which limits exposure through the normal intent flow. However, `openUrl` is exported for other callers, and the module directly accepts `process.argv[2]` when run as a command-line program. ### Attack Path 1. An attacker obtains control over a URL supplied to the exported `openUrl` function or the script's first command-line argument. 2. The attacker supplies an HTTPS URL whose hostname passes the `i.beautsgo.com` allowlist. 3. Th ...[truncated 817 chars]- Remediation
View remediation
