T09 · Insecure Skill Coding Practices
- Location
scripts/v2ray-proxy.sh:180- Finding
Arbitrary Command Execution Through Unsafe eval Usage
- Content
View full analysis
Vulnerability Details
File Location:
scripts/v2ray-proxy.sh, lines 180–194
Vulnerability Type: OS command injection
Risk Level: HighVulnerable Code
bash wrap() { local cmd="$*" log_info "执行命令: $cmd" # 检查是否需要代理 if check_network; then log_info "网络正常,直接执行..." eval "$cmd" return $? fi # 需要代理,开启后执行 log_info "开启代理后执行..." proxy_on local result=0 eval "$cmd" || result=$? log_info "命令执行完成,关闭代理..." proxy_off return $result }Technical Analysis
The
wrapfunction combines all supplied arguments into a single string using"$*", then passes that string toeval. Unlike direct argument-array execution,evalasks the shell to parse the resulting string again. Shell metacharacters, command substitutions, redirections, pipelines, and additional commands embedded in an argument therefore become executable syntax.Quoting
"$cmd"at the point where it is passed toevaldoes not prevent injection becauseevaldeliberately performs another shell parsing pass.Attack Path
- An attacker controls or influences arguments passed to the
wrapcommand, directly or through another workflow. - The attacker includes shell syntax such as command substitution or a command separator in an argument.
- The script flattens the argument list into
cmdwithlocal cmd="$*". - Either network branch reaches
eval "$cmd". - The shell reparses the injected syntax and executes the unintended command.
For example, a literal argument containing
$(unintended-command)would be evaluated as command substitution rather than being passed unchanged to the intended program.Impact Assessment
Successful exploitation provides arbitrary command execution with the privileges of the user running the script. The attacker could read or modify files available to t ...[truncated 277 chars]
- An attacker controls or influences arguments passed to the
- Remediation
View remediation
Remediation Suggestions
Preserve the original argument boundaries and execute the command directly without
eval:bash wrap() { local result=0 log_info "Executing wrapped command" if check_network; then log_info "Network is available; executing directly" "$@" return $? fi log_info "Enabling proxy before execution" proxy_on "$@" || result=$? log_info "Command completed; disabling proxy" proxy_off return "$result" }Additional hardening measures:
- Reject an empty command before attempting execution.
- Do not reconstruct commands as strings.
- If only specific programs are expected, enforce an allowlist of permitted executable names.
- Avoid logging untrusted arguments without safe escaping, especially when logs may be consumed by terminals or parsers.
- Run wrapped commands with the minimum required operating-system privileges.
