T09 · Insecure Skill Coding Practices
- Location
scripts/sleep.sh:9- Finding
Predictable Shared Temporary File Exposes Sleep Journal Data and Enables Symlink Attacks
- Content
View full analysis
Vulnerability Details
File Location:
scripts/sleep.sh, lines 9 and 470
Vulnerability Type: Predictable unsafe temporary file
Risk Level: Mediumbash JOURNAL_FILE="/tmp/sleep_journal.txt"bash echo "${date} | ${bedtime}-${waketime} | ${sleep_h}h${sleep_m}m | Q:${quality}/10 | ${notes}" >> "$JOURNAL_FILE"Technical Analysis
The script stores health-related sleep journal records at a fixed, predictable path in the globally shared
/tmpdirectory. It neither creates the file with an explicitly restrictive permission mode nor verifies that the destination is a regular file owned by the current user.An attacker with local access can anticipate the path and pre-create the file, manipulate its permissions, or replace it with a symbolic link. Shell append redirection follows symbolic links, so the journal entry can be redirected to another file writable by the victim. An attacker can also seed fabricated records that will subsequently appear in the journal's seven-day history.
Attack Path
- A local attacker predicts the fixed path
/tmp/sleep_journal.txt. - Before the victim invokes the journal command, the attacker creates that file with permissive access or creates a symbolic link at that path to another victim-writable file.
- The victim runs a command such as
bash sleep.sh journal .... - The shell follows the existing path and appends the journal entry using the victim's privileges.
- Depending on the attack setup, the attacker can read sensitive sleep records, inject false history, corrupt the journal, or cause attacker-selected data to be appended to another file writable by the victim.
Impact Assessment
The vulnerability can disclose health-related sleep times, quality ratings, and free-form notes to another local user. It can also compromise journal integrity through record injection or corruption.
A successful symlink attack permits append operations with the invoking user's privileges, but only aga ...[truncated 225 chars]
- A local attacker predicts the fixed path
- Remediation
View remediation
Remediation Suggestions
- Store the journal in a private per-user data directory, such as
${XDG_DATA_HOME:-$HOME/.local/share}/sleep-tracker. - Create the directory with mode
0700and the journal file with mode0600. - Set a restrictive
umask, such asumask 077, before creating or writing sensitive files. - Before writing, reject symbolic links and verify that an existing destination is a regular file owned by the current user.
- Avoid fixed names in shared temporary directories. If temporary storage is genuinely required, create a private directory or file with
mktempand arrange secure cleanup. - Use atomic, race-resistant file operations where possible rather than performing a separate check followed by ordinary shell redirection.
A hardened storage setup could begin with:
bash DATA_DIR="${XDG_DATA_HOME:-$HOME/.local/share}/sleep-tracker" umask 077 mkdir -p -- "$DATA_DIR" chmod 700 -- "$DATA_DIR" JOURNAL_FILE="$DATA_DIR/sleep_journal.txt" if [ -L "$JOURNAL_FILE" ]; then echo "Refusing to write through a symbolic link" >&2 exit 1 fi- Store the journal in a private per-user data directory, such as
