T09 · Insecure Skill Coding Practices
- Location
jits.sh:45- Finding
Arbitrary JavaScript Execution Through Unsanitized Port and App Name Arguments
- Content
View full analysis
{ res.writeHead(200, {'Content-Type': 'text/html'}); res.end(html); }).listen($port, () => console.log('JITS server on port $port')); " & echo $! > "$JITS_DIR/$name.pid" echo "$port" > "$JITS_DIR/$name.port" echo "✅ Serving $name on port $port" ``` ### Technical Analysis The `name` and `port` command-line arguments are inserted directly into JavaScript source passed to `node -e`. They are neither syntactically encoded nor constrained to safe values. The `port` value is particularly exploitable because it is inserted as raw JavaScript inside the argument list of `listen()`: ```javascript .listen($port, () => ...) ``` An attacker able to invoke the script can supply JavaScript syntax instead of a numeric port, terminate the intended expression, and append arbitrary Node.js statements. Node.js exposes filesystem, process, and child-process APIs, so injected code can execute operating-system commands with the privileges of the account running the Skill. The `name` argument is also embedded inside a single-quoted JavaScript string in `fs.readFileSync()`. A crafted value containing quote characters and JavaScript syntax could escape that string if the corresponding path-validation precondition can be satisfied. ### Attack Path 1. The attacker gains the ability to invoke `jits.sh serve`, direc ...[truncated 1336 chars]- Remediation
View remediation
65535) { throw new Error("Invalid port"); } const html = fs.readFileSync(htmlFile, "utf8"); http.createServer((req, res) => { res.writeHead(200, {"Content-Type": "text/html"}); res.end(html); }).listen(port); ' ``` 3. Restrict app names to a conservative allowlist, such as `^[A-Za-z0-9_-]+$`. 4. Require the port to contain digits only and enforce the range `1` through `65535`. 5. Prefer a separate static Node.js server file instead of dynamically generated `node -e` source. 6. Add negative tests covering quotes, semicolons, parentheses, newlines, path separators, and JavaScript comment syntax. ]]>
