T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:64- Finding
Unsafe JSON and CSV Generation from Untrusted Log Values
- Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; ``` ### Technical Analysis Values read from the log files are derived from command-line input and therefore must be treated as untrusted. The export implementation inserts these values directly into JSON strings without escaping quotation marks, backslashes, control characters, or line breaks. A crafted value can consequently invalidate the generated document or inject additional JSON properties and objects. The CSV implementation similarly concatenates fields without RFC 4180 quoting. Commas, quotation marks, and newlines can alter the exported record structure. In addition, a value beginning with `=`, `+`, `-`, or `@` may be interpreted as a formula when the file is opened in spreadsheet software. Depending on the spreadsheet and its security settings, such a formula may initiate external requests, disclose data, or mislead the user. The current command dispatcher cont ...[truncated 1588 chars]- Remediation
View remediation
