T09 · Insecure Skill Coding Practices
- Location
monitor.js:8- Finding
OS Command Injection Through the Unvalidated Remote Host Argument
- Content
View full analysis
Vulnerability Details
File Location:
monitor.js, lines 8-24
Vulnerability Type: OS command injection
Risk Level: HighVulnerable Code:
javascript const remoteHost = args.includes('--remote') ? args[args.indexOf('--remote') + 1] : null;javascript function run(cmd, timeout = 8000) { try { return execSync(cmd, { timeout, encoding: 'utf8', stdio: ['pipe','pipe','pipe'] }).trim(); } catch { return null; } } function remoteRun(cmd) { const escaped = cmd.replace(/"/g, '\\"'); return run(`ssh -o ConnectTimeout=3 -o StrictHostKeyChecking=no ${remoteHost} "${escaped}"`); }Technical Analysis
The value of
remoteHostis read directly from the command-line arguments and interpolated into a command string passed toexecSync. BecauseexecSyncexecutes the string through a shell, shell metacharacters contained inremoteHostare interpreted as command syntax.The script only escapes double quotes in the remote command stored in
cmd. It performs no validation or shell escaping ofremoteHost, which occupies an unquoted position in the generated SSH command. Consequently, an attacker who can influence the--remoteargument can terminate or modify the intended SSH command and cause an additional local command to run.The broad exception handler does not mitigate this vulnerability. An injected command can execute before
execSyncreturns or throws, while the error is then silently discarded.Attack Path
- An attacker gains control over, or persuades an agent or user to supply, the value following
--remote. - The attacker supplies a value containing shell control syntax rather than a valid
user@hosttarget. remoteRun()inserts that value directly into the SSH command string.run()passes the constructed string toexecSync.- The local shell interprets the injected syntax and executes the attacker-controlled command with the privileges o ...[truncated 700 chars]
- An attacker gains control over, or persuades an agent or user to supply, the value following
- Remediation
View remediation
Remediation Suggestions
- Replace shell-based
execSyncuse withexecFileSyncorspawnSync, passing the executable and each argument separately. For example, invokesshwith an argument array rather than constructing a shell command string. - Validate
remoteHostagainst a strict allowlist grammar supporting only the required hostname, IP address, and optional username formats. - Reject absent values, whitespace, control characters, shell metacharacters, and values beginning with a hyphen.
- Use an explicit end-of-options marker where supported to prevent a target from being interpreted as an SSH option.
- Do not rely on manual quote replacement as a substitute for eliminating shell interpretation.
- Return a clear error for invalid input instead of silently converting execution failures to
null. - Add automated tests covering malicious metacharacters, option injection, missing
--remotevalues, IPv4/IPv6 targets, and validuser@hosttargets.
- Replace shell-based
