T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:64- Finding
Unescaped User Content Enables JSON Structure Injection
- Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` ### Technical Analysis The `value` field originates from user-supplied content stored in log files. It is interpolated directly into a JSON string without escaping JSON metacharacters such as double quotes, backslashes, carriage returns, or control characters. An attacker can submit content containing a quote followed by additional JSON syntax. When the data is exported, this content can terminate the intended string and inject fields, objects, or malformed structure into `export.json`. Because the script constructs JSON through `printf` rather than a standards-compliant serializer, the resulting file cannot safely preserve arbitrary user input. ### Attack Path 1. An attacker or untrusted user supplies crafted text to a content command, such as `draft`. 2. The command stores that text verbatim in a log under `~/.local/share/movie-review/`. 3. A user invokes `movie-review export json`. 4. `_export` reads the attacker-controlled value and inserts it directly between JSON quotation marks. 5. The crafted characters alter or invalidate the exported JSON structure. 6. A downstream service that trusts and processes the export may consume attacker-created fields or records, depending on its parsing and validation behavior. ### Impact Assessment The vulnerability does not directly grant shell execution or additional operating-system privileges. Its scope is the integrity and availabi ...[truncated 396 chars]- Remediation
View remediation
