T09 · Insecure Skill Coding Practices
- Location
browser-manager.v2.js:61- Finding
Shell Command Injection in Browser Command Execution
- Content
View full analysis
{ const attempt = (n) => { this.logger.debug(`Exec: ${cmd} (attempt ${n + 1})`); exec(cmd, { timeout }, async (err, stdout, stderr) => { if (err) { this.logger.warn(`Command failed: ${stderr || err.message}`); if (n < retries && /ENETUNREACH|ECONNREFUSED|ETIMEDOUT/.test(stderr || '')) { const backoff = 1000 * Math.pow(2, n); this.logger.info(`Retrying in ${backoff}ms...`); await new Promise(r => setTimeout(r, backoff)); return attempt(n + 1); } reject({ err, stdout, stderr, attempt: n + 1 }); } else { resolve({ stdout, stderr }); } }); }; attempt(0); }); } ``` Representative vulnerable call sites include: ```js await this.runCommand(`openclaw browser --browser-profile ${this.profile} open "${url}"`); await this.runCommand(`openclaw browser --browser-profile ${this.profile} type ${ref} "${text}"`); await this.runCommand(`openclaw browser --browser-profile ${this.profile} press ${key}`); ``` ### Technical Analysis `child_process.exec()` runs its input through a system shell. The command strings are assembled through template interpolation using values that can originate from command-line arguments or environment variables, including: - URLs supplied to `fetch-summary.js`, `multi-pages.js`, or benchmark mode - Form values supplied to `fill-form.js` - Search terms supplied to `search-google.js` - `BROWSER_PROFILE` - Othe ...[truncated 1891 chars]- Remediation
View remediation
