T09 · Insecure Skill Coding Practices
- Location
scripts/replay-stripe-webhook.sh:113- Finding
Stripe webhook secret exposed through process command-line arguments
- Content
View full analysis
/cmdline`, subject to the operating system's process visibility and permission configuration. Although the OpenSSL process is short-lived, the operation is repeated for every replay attempt, increasing the opportunity for a local process to observe the argument. The secret authorizes generation of valid Stripe webhook signatures and should not be copied into process arguments. ### Attack Path 1. A legitimate user executes the replay script with a valid Stripe webhook endpoint secret. 2. A local attacker or monitoring process with permission to inspect the user's processes repeatedly enumerates command lines. 3. During an OpenSSL invocation, the attacker captures the value supplied after `-hmac`. 4. The attacker uses the recovered secret to compute HMAC-SHA256 signatures for attacker-controlled Stripe event payloads. 5. The forged requests are sent to an endpoint configured to trust that webhook secret. Exploitation requires local process visibility or an equivalent process-monitoring capability. ### Impact Assessment Disclosure of the endpoint secret allows an attacker to forge webhook signatures accepted by applications using the same secret. The resulting application-level impact depends on the webhook handler's behavior and may includ ...[truncated 319 chars]- Remediation
View remediation
