T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:64- Finding
Unescaped User Input Allows JSON Export Injection
- Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` ### Technical Analysis The application inserts log data directly into a JSON document using string formatting. The `val` field originates from user-controlled command arguments and is not JSON-escaped before serialization. Shell quoting prevents shell command injection at this location, but it does not provide JSON encoding. Characters such as double quotes, backslashes, carriage returns, newlines, and control characters can therefore invalidate the generated document or modify its logical structure. For example, a value containing closing quotes and additional JSON syntax can introduce fabricated fields or records into the export. Any downstream program that treats the exported document as trusted structured data may process attacker-created content. ### Attack Path 1. An attacker convinces a user to save a crafted bookmark or other entry containing JSON syntax, such as embedded quotes and object delimiters. 2. The application writes the value to one of its local log files. 3. The user runs `bookmark-keeper export json`. 4. `_export` interpolates the crafted value into `export.json` without JSON escaping. 5. The resulting file is malformed or contains attacker-controlled JSON structure. 6. A downstream parser, importer, or automation process may reject the export or process fabricated data. ### Impact Assessment The direct impact is limited to data generated under the current user's account. The vulnerability can corrupt exported data, create misleading records, and affect downstream systems that import the JSON. The script itself does not grant additional ope ...[truncated 152 chars]- Remediation
View remediation
