T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:62- Finding
Improper Escaping of User-Controlled Data in JSON Exports
- Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` ### Technical Analysis The export routine inserts log contents directly into JSON string literals without applying JSON escaping. The `value` field can contain user-controlled command arguments previously recorded in a log file. Quotes, backslashes, newlines, and other JSON control characters are therefore written verbatim. Shell quoting around `"$val"` prevents shell word splitting and command substitution at export time, but it does not make the value safe for a JSON context. A crafted entry can terminate the expected string, add properties or objects, or make the exported document syntactically invalid. For example, a stored value resembling the following can alter the logical structure of the output: ```text x","injected":true,"value":"y ``` This is an output-encoding vulnerability rather than direct shell command injection. ### Attack Path 1. An attacker or untrusted caller supplies a crafted value to an argument-bearing command such as `dice score`. 2. The application records the value without validating or encoding it. 3. The user invokes `dice export json`. 4. The export routine interpolates the crafted value directly into a JSON string. 5. A downstream program consumes the resulting export. 6. Depending on the payload, the JSON is rejected, interpreted with attacker-injected fields, or processed differently from the structure intended by the application. ### Impact Assessment The vulnerability can compromise the integrity and availability of generated JSON exports. It may permit injection of misleading fields or records into data consumed by another application. The impact ...[truncated 238 chars]- Remediation
View remediation
