T09 · Insecure Skill Coding Practices
Error
- Location
analyzer.sh:19- Finding
Unvalidated Numeric Arguments Permit Bash Arithmetic Command Injection
- Content
View full analysis
/dev/null || echo "0") local daily_avg=$(echo "scale=1; $total / $days" | bc 2>/dev/null || echo "0") echo "" echo -e "${BOLD}📊 Full Git Analysis (last ${days} days)${NC}" echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" echo "" echo -e "${BOLD}Overview${NC}" echo " Total commits: $total" echo " Daily average: $daily_avg" echo " Commits/hour: $cph" echo "" echo -e "${BOLD}Daily Breakdown${NC}" for i in $(seq 0 $((days - 1))); do ``` The `waiting` command similarly accepts the same unvalidated parameter for subsequent arithmetic processing: ```bash detect_waiting() { local hours=${PARAM:-48} ``` ### Technical Analysis The second positional argument is accepted without checking that it contains only a bounded positive integer. For the `report` command, this value is assigned to `days` and evaluated inside Bash arithmetic expansions such as: ```bash $((days * 24)) $((days - 1)) ``` Bash arithmetic evaluation can recursively interpret the value of a referenced variable as an arithmetic expression. Specially constructed values may therefore trigger shell expansions, including command substitution in applicable arithmetic expressions, rather than being treated strictly as numeric data. The same input also reaches `seq`, `git log`, `bc`, and date-related operations without validation. Even when a payload does not achieve command execution, malformed or extremely large values can cause ...[truncated 1497 chars]- Remediation
View remediation
&2 exit 2 fi if (( value > maximum )); then echo "Parameter exceeds the permitted maximum of $maximum." >&2 exit 2 fi } ``` Apply command-specific limits before dispatch: ```bash case "$COMMAND" in report|hourly|categories) validate_positive_integer "$PARAM" 365 ;; waiting) validate_positive_integer "$PARAM" 8760 ;; esac ``` Additional hardening should include: 1. Use `local days="$PARAM"` and quote arguments passed to ordinary commands. 2. Reject signs, whitespace, shell metacharacters, variable names, array syntax, and arithmetic operators. 3. Apply conservative upper bounds to prevent oversized loops and expensive Git history scans. 4. Use `printf` for error messages and return a nonzero status on invalid input. 5. Add regression tests containing command substitutions, arithmetic expressions, negative values, empty values, decimals, whitespace, and very large integers. ]]>
