T09 · Insecure Skill Coding Practices
- Location
utils.py:75- Finding
API Key Stored Without Enforced File Permissions
- Content
View full analysis
Vulnerability Details
File Location:
utils.py, lines 5-7 and 75-77
Vulnerability Type: Plaintext credential storage with inherited permissions
Risk Level: MediumVulnerable Code
python JIUMA_API_KEY_SAVE_DIR = f"{os.path.dirname(os.path.dirname(os.path.dirname(os.path.abspath(__file__))))}/.jiuma" os.makedirs(JIUMA_API_KEY_SAVE_DIR, exist_ok=True) JIUMA_API_KEY_SAVE_PATH = f"{JIUMA_API_KEY_SAVE_DIR}/jiuma_api_key"python def save_jiuma_api_key(api_key): with open(JIUMA_API_KEY_SAVE_PATH, "w") as f: f.write(api_key)Technical Analysis
The API key is written as plaintext using the process's default
umask. The code does not explicitly restrict the directory to mode0700or the credential file to mode0600. Therefore, the effective permissions depend on the host configuration and may allow other local users or processes to read the credential.This also conflicts with the documentation's assertion that only the current user can read the key. Plaintext storage is not inherently avoidable for every command-line application, but enforcing owner-only access is the minimum necessary protection for a reusable API credential.
Attack Path
- The user completes the QR login workflow.
login.pyobtains asecret_keyfrom the remote service.save_jiuma_api_key()creates or overwrites.jiuma/jiuma_api_keyusing inherited permissions.- On a system with a permissive
umask, another local account or compromised process reads the file. - The attacker submits requests to the Jiuma API using the stolen key.
Exploitation requires local filesystem access and sufficiently permissive effective permissions.
Impact Assessment
A successful attacker can obtain the stored Jiuma API credential and exercise the API privileges associated with the victim's account. This may consume the victim's quota, submit unauthorized image-processing jobs, or expose a ...[truncated 181 chars]
- Remediation
View remediation
Remediation Suggestions
- Create the credential directory with owner-only permissions:
python os.makedirs(JIUMA_API_KEY_SAVE_DIR, mode=0o700, exist_ok=True) os.chmod(JIUMA_API_KEY_SAVE_DIR, 0o700) - Create the key file atomically with mode
0600, preferably usingos.open()withO_CREAT | O_WRONLY | O_TRUNCand an explicit mode. - Write to a protected temporary file and atomically replace the destination to avoid partial writes.
- Check and correct permissions on existing key files before reading them.
- Where available, use an operating-system credential store instead of a plaintext file.
- Never print the API key or include it in exceptions and diagnostic logs.
- Create the credential directory with owner-only permissions:
