T09 · Insecure Skill Coding Practices
- Location
send_attachment.py:115- Finding
OS Command Injection Through the msmtp Recipient Argument
- Content
View full analysis
/tmp/email-reporter-pwned # ``` 3. `email_reporter.py` forwards the recipient to `send_attachment.py`. 4. `send_via_msmtp()` constructs the following effective shell command: ```sh cat /tmp/email_reporter_msg.eml | msmtp -t victim@example.com; id > /tmp/email-reporter-pwned # ``` 5. The shell executes the injected command with the privileges of the user or agent running the skill. ### Impact Assessment Successful exploitation provides arbitrary command execution under the account running the email reporter. An attacker could read or alter files available to that account, steal environment variables and SMTP credentials, modify reports, invoke network tools, or use the compromised proc ...[truncated 198 chars]- Remediation
View remediation
