T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:58- Finding
Unsafe JSON and CSV Export Serialization
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 58-80
Vulnerability Type: Improper output encoding and CSV formula injection
Risk Level: Mediumbash _export() { local fmt="${1:-json}" local out="$DATA_DIR/export.$fmt" case "$fmt" in json) echo "[" > "$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "\n]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" done ;;Technical Analysis
Log values originate from command-line input and are stored without validation. During export, these values are interpolated directly into JSON strings and CSV fields without format-specific escaping.
In JSON output, embedded quotation marks, backslashes, and control characters can terminate or alter string values, corrupting the document or injecting attacker-controlled JSON structure. The generated closing line also uses
echo "\n]", whose handling of the backslash is implementation-dependent and can further produce invalid JSON.In CSV output, commas, quotation marks, carriage returns, and line feeds are not encoded according to CSV rules. More importantly, values beginning with spreadsheet formula indicators such as
=,+,-, or@remain executable fo ...[truncated 1560 chars]- Remediation
View remediation
Remediation Suggestions
- Generate JSON with a serializer that correctly escapes all string values. For example, use
jq -nwith--argparameters rather than constructing JSON withprintf. - Generate the complete JSON array through the serializer and validate it before reporting a successful export.
- Encode CSV according to RFC 4180: enclose each field in double quotes, replace every embedded double quote with two double quotes, and preserve record boundaries safely.
- Neutralize spreadsheet formulas in user-controlled CSV fields. If spreadsheet use is intended, prefix values beginning with
=,+,-, or@with an apostrophe or apply another documented formula-injection mitigation. - Add regression tests covering quotation marks, backslashes, commas, pipes, carriage returns, line feeds, Unicode, and formula-leading values.
- Treat exports as untrusted data and document that CSV files should not be opened in spreadsheet applications without appropriate formula-evaluation protections.
- Generate JSON with a serializer that correctly escapes all string values. For example, use
