T09 · Insecure Skill Coding Practices
- Location
" [ -f $2 ] && grep -q 'query\|mutation\|type' $2 && echo 'Valid GraphQL file' || echo 'Invalid' } cmd_format() { local file="${2:-}" [ -z "$file" ] && die "Usage: $SCRIPT_NAME format <file>" cat $2 2>/dev/null | sed 's/{/{ /g' | sed 's/}/ }/g' } cmd_introspect() { local url="${2:-}" [ -z "$url" ] && die "Usage: $SCRIPT_NAME introspect <url>" curl -s -X POST -H 'Content-Type: application/json' -d '{"query":"{__schema{types{name}}}"}' $2 2>/dev/null } cmd_schema() { local ...[truncated 3506 chars]:99- Finding
Curl Option Injection Enables Local File Exfiltration and Arbitrary File Overwrite
- Content
View full analysis
" [ -f $2 ] && grep -q 'query\|mutation\|type' $2 && echo 'Valid GraphQL file' || echo 'Invalid' } cmd_format() { local file="${2:-}" [ -z "$file" ] && die "Usage: $SCRIPT_NAME format " cat $2 2>/dev/null | sed 's/{/{ /g' | sed 's/}/ }/g' } cmd_introspect() { local url="${2:-}" [ -z "$url" ] && die "Usage: $SCRIPT_NAME introspect " curl -s -X POST -H 'Content-Type: application/json' -d '{"query":"{__schema{types{name}}}"}' $2 2>/dev/null } cmd_schema() { local file="${2:-}" [ -z "$file" ] && die "Usage: $SCRIPT_NAME schema " cat $2 2>/dev/null | grep -E '^type |^input |^enum ' | head -20 } ``` ### Technical Analysis The user-controlled `$2` parameter is expanded without double quotes in commands including `curl`, `cat`, `grep`, and the shell file test. Bash consequently applies word splitting and pathname expansion to the supplied value. This is particularly dangerous in `cmd_introspect`. A value containing spaces is converted into multiple curl arguments, and words beginning with `-` are interpreted as curl options rather than as a URL. This is argument injection, not direct shell metacharacter command injection: injected shell operators are not reparsed, but arbitrary curl options can still substantially change the request. For example, an injected `--data-binary @` option can instruct curl to read a local file and include it in an outbound request. An injected `--output ` option can make curl write the response to an attacker-selected path. The dispatcher shifts the command name before invoking each handler, while the handlers incorrectly read `$2` rather than `$1` ...[truncated 2228 chars]- Remediation
View remediation
/dev/null`. Use `-sS`, check the exit status, set connection and transfer timeouts, and impose a response-size limit where practical. 7. Apply shell linting, such as ShellCheck, in continuous integration. Rules concerning unquoted expansions would identify each affected command. ]]>
