T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:57- Finding
Improper Output Encoding in JSON and CSV Exports
- Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; ``` ### Technical Analysis Diary entry values are user-controlled and are written directly into JSON and CSV exports without format-specific encoding. For JSON output, quotation marks, backslashes, control characters, and embedded newlines are not escaped. An entry containing these characters can terminate the intended JSON string, inject additional JSON properties or objects, or make the exported document syntactically invalid. For CSV output, fields are not enclosed in quotes and embedded quotes are not escaped. Commas and newlines can therefore alter the exported row and column structure. In addition, values beginning with spreadsheet formula indicators such as `=`, `+`, `-`, or `@` may be interpreted as formulas when the resulting CSV file is opened in compatible spreadsheet software. This issue does not constitute shell command injection in the diary script itself because the values are passed as quoted arguments to `printf` or `echo`. Exploit ...[truncated 1768 chars]- Remediation
View remediation
